Dashboards & Visualizations

How can I use the correct index when using the GUI with opsec lea checkpoint add-on?

a599korg
Explorer

When I use the GUI for opsec lea check point add on it only recognises the default index. Apart from manually changing the files (which works) how can I get it to recognise the correct index? Does it reference a particular list of indexes?
Any help would be really useful.

0 Karma

ejenson
Explorer

You need to ensure the index exists on the machine you are configuring the OpsecLEA client. We had this same issue. If you are using a heavy forwarder the data won't be stored on there anyway.

Get Updates on the Splunk Community!

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and ...

Full-Stack Security in Financial Services: AppDynamics, Cisco Secure Application, and Splunk ES Protecting a ...

It's Customer Success Time at .conf25

Hello Splunkers,   Ready for .conf25? The customer success and experience team is and can’t wait to see you ...

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...