Getting Data In

Checkpoint LEA App working issue: all logs entries are downloaded at each script execution

LauMat
Engager

Hello,

We are a consulting firm and I am assessing the Splunk solution for one of my customer.

The LEA application for Checkpoint is not working correctly : each time the script is called, it downloads the complete fw.log file. It results with a huge data indexing activity - and license expiration warnings!

I assume the script should normally download the difference since last LEA download.

Could somebody help to clarify how it works and what might going wrong with our installation?

Your help appreciated. Many thanks.

Laurent

treyka
Path Finder

Hey, LauMat, did you solve this problem? If not, double-check the permissions on your lea_loggrabber app(s) - the lea app stores its state in bin/ but whatever user this app is running as needs write permission to some of the files in this directory. In your case I believe that it is (or was) unable to write to lea_log_rec_num.cache which is where it keeps track of the last line read off the wire.

treyka
Path Finder

(For debugging lea_loggrabber issues it can be useful to execute the command with strace (plus the lea_loggrabber --debug flag).

Lowell
Super Champion

If you don't get an answer here, you should try contacting splunk support: Simply email support@splunk.com, or give them a call.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...