All Apps and Add-ons

Does the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80?

tallan
Engager

Will the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80? We are in the process of doing an early upgrade on all Checkpoint managers and log servers to R80. The older version of Checkpoint that we were on, R77, is currently supported by the OPSEC LEA add-on and has functioned properly since installation, but I do not see any information or release dates for support of R80. Has anyone tried R80 and the OPSEC LEA add-on?

0 Karma
1 Solution

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

View solution in original post

FrankVl
Ultra Champion

Given that R80 supports syslog forwarding, you might want to take a look a that. Could make your checkpoint data collection a lot easier. You'd need to create a custom TA for it, since the official add-on does not support the syslog format, but apart from the basic field extractions, you can re-use a lot of logic from the original TA.

0 Karma

tonisaprano
New Member

But starting with version 4.0.0 release notes tell that Add-on supports R80. (vendor Products Check Point OPSEC LEA R76, R77, R80). Actually has anybody tried R80 and the OPSEC LEA add-on?

0 Karma

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...