- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Add-on for Check Point OPSEC LEA: Unable to add LEA connection with error "Unauthorized client for the requested action..."
gpittmon
New Member
06-28-2016
07:54 AM
When trying to add a new (CMA) connection, I am getting this error:
REST ERROR[403]: Unauthorized client for the requested action - Client is not authorized to perform requested action
What am I missing?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

mreynov_splunk

Splunk Employee
06-28-2016
10:36 AM
What version of the addon are you working with?
Did you do the pull cert step?
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
gpittmon
New Member
06-28-2016
12:19 PM
Hello mreynov, we are running Splunk version 6.3.1. The Splunk Add-on for Check Point OPSEC LEA is v 4.0.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

mreynov_splunk

Splunk Employee
06-28-2016
12:28 PM
You need to get the cert from OPSEC to establish SIC.
