Dashboards & Visualizations

How can I use the correct index when using the GUI with opsec lea checkpoint add-on?

a599korg
Explorer

When I use the GUI for opsec lea check point add on it only recognises the default index. Apart from manually changing the files (which works) how can I get it to recognise the correct index? Does it reference a particular list of indexes?
Any help would be really useful.

0 Karma

ejenson
Explorer

You need to ensure the index exists on the machine you are configuring the OpsecLEA client. We had this same issue. If you are using a heavy forwarder the data won't be stored on there anyway.

Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...