All Apps and Add-ons

What is the difference between the new OPSEC LEA app and the old one?

a212830
Champion

What's the difference between this one and the existing one? It appears that the functionality is the same - you've just put a admin gui in front of it. Still waiting on a persistent/real-time connection - not a script that wakes up every xx seconds.

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

The Splunk TA for Opsec LEA has been completely redesigned and reimplemented for vastly improved speed, scale and reliablity, much better configurability and usability, a convenient UI, enhanced support for the most popular Checkpoint platforms including Provider-1/CMA R70/75.1/75.4, complete install and configuration documentation, support for audit logs and no-resolve mode, improved debugging, several critical bug fixes, a new knowledge layer for the data collected from Firewall/CMA, and a lot more.

It is too bad that the standard polling impletementation does not work for your use case. If you could explain in detail why persistent connections are better than polling for you, we will add it to your existing enhancement request for this feature and consider it for a future version of the product.

View solution in original post

araitz
Splunk Employee
Splunk Employee

The Splunk TA for Opsec LEA has been completely redesigned and reimplemented for vastly improved speed, scale and reliablity, much better configurability and usability, a convenient UI, enhanced support for the most popular Checkpoint platforms including Provider-1/CMA R70/75.1/75.4, complete install and configuration documentation, support for audit logs and no-resolve mode, improved debugging, several critical bug fixes, a new knowledge layer for the data collected from Firewall/CMA, and a lot more.

It is too bad that the standard polling impletementation does not work for your use case. If you could explain in detail why persistent connections are better than polling for you, we will add it to your existing enhancement request for this feature and consider it for a future version of the product.

a212830
Champion

Thanks for the info. The checkpoint data is used for security purposes, which requires a real-time, persistent feed, not a script that is going to wake up every xx seconds.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...