All Apps and Add-ons

Collect log from CheckPoint OPSEC Lea to Splunk Enterprise install on Windows OS

mindterrian
New Member

Hi

How can i collect the CheckPoint OPSEC Lea on Splunk Enterprise that install on Windows OS?
Because this guide (https://docs.splunk.com/Documentation/AddOns/released/OPSEC-LEA/Hardwareandsoftwarerequirements) only support on Linux OS.

Thank you

Tags (1)
0 Karma

vishaltaneja070
Motivator

Hello @mindterrian

As per the above document, the add-on supports on Linux in case if you are using Universal Forwarder to collect data.

If you are using any other component like search head or indexer , they can be on any platform.

0 Karma

mindterrian
New Member

Hello @vishaltaneja07011993

My environment is
Splunk Enterprise (Single Instance) install on Windows Werver 2012 R2 and install Splunk Add-on for Check Point OPSEC LEA already.
I can use this Splunk Server to collect log from Check Point via add parameter on Splunk Add-on for Check Point OPSEC LEA right?

Or i need to install Universal forwarder on Linux OS and install Splunk Add-on for Check Point OPSEC LEA after that i will collect log via Universal forwarder?

Thank you

0 Karma

mindterrian
New Member

I can use Splunk Enterprise (Single Instance) that install on Windows OS to collect log from Check Point OPEC LEA via install Splunk Add-on for Check Point OPSEC LEA and Add connect right?

or i should install universal forwarder on Linux OS and use Splunk Add-on for Check Point OPSEC LEA on Linux OS to collect log from Check Point?

0 Karma

dkeck
Influencer

There is an alternate option where you can analyze checkpoint logs via syslog. This add-on will help you analyze Check Point logs on Windows.

https://splunkbase.splunk.com/app/2996/

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...