I am very confused about these two params from Splunk Add-on for Check Point OPSEC LEA Linus:
According to Splunk documentation on page 32, it states that "the inputs.conf disabled state must match the
opsec.conf is_disabled state", the questions are
Thanks.
hi, I think that the inputs.conf disabled is the really important one, without that set to disabled you will continue to get data into Splunk.