Getting Data In

Checkpoint OPSEC LEA 4.1 manual log input and multiple HF's

mmoermans
Path Finder

Due to the lea_loggrabber script malfunctioning (reason unkown, not to be found in logging) we are missing 4 days worth of checkpoint logging. A restart of the heavy forwarder fixed the issue.

What's the best practice for reading those 4 days worth of binary files back into Splunk through the OPSEC LEA process?
A monitor doesn't seem to work from inputs.config.

Second question: How can you create a backup for the OPSEC LEA process so that if it fails (like happened) another Heavy Forwarder can pick it up and input the data instead?

0 Karma

bheemireddi
Communicator

Hi mmoermans,

Since you mentioned you are using version 4.1 of OPSEC, when you noticed outage time, if you login to the Splunk UI and go to configuring inputs in the checkpoint add-on - you will see "StartTime". You can change that to the start time you want to pull the logs. (it can only go back to the beginning of the log fw.log on checkpoint side, but if the file is already rolled off on that side, you wouldn't be able to get those logs)

You can have a standby Heavy forwarder with the same configurations (connections,certs, inputs etc) of the active forwarder, except in the case of outage, you can bring it online and have the startTime configured on the standby and start the forwarder. Basically you just need to configure the stanby similar to active and you only run it when needed

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...