Getting Data In

Filter Origin from LEA_OPSEC Input

simuvid
Splunk Employee
Splunk Employee

Hi all,

I have posted a similar question before, but I think I was not specific enough.

What I mean is, when getting events as a data input from Checkpoint Devices, include by using LEA_OPSEC, all of these events are listed and shown as one host and source. In the events listing I see multiple different origins of the events, so my question is:

Is there a possibility to filter these different origins, before indexing them, to display them by as source or host related to their origin?

Hope that is a bit clearer 🙂

Cheers,

Christian

Tags (2)
0 Karma
1 Solution

mmletzko
Path Finder

Christian,

You can add a "host = " line in your /opt/splunk/etc/system/local/inputs.conf file. It would look something like this:

[script:/opt/splunk/etc/apps/lea-loggrabber-xxx_xxx/bin/lea-loggrabber.sh]
host = xxx_xxx
interval = 60
sourcetype = opsec
disabled = false

After making the change, stop/start splunk and you should see the host now showing up instead of the name of the box this is configured on.

-Matt

View solution in original post

0 Karma

mmletzko
Path Finder

Christian,

You can add a "host = " line in your /opt/splunk/etc/system/local/inputs.conf file. It would look something like this:

[script:/opt/splunk/etc/apps/lea-loggrabber-xxx_xxx/bin/lea-loggrabber.sh]
host = xxx_xxx
interval = 60
sourcetype = opsec
disabled = false

After making the change, stop/start splunk and you should see the host now showing up instead of the name of the box this is configured on.

-Matt

0 Karma

simuvid
Splunk Employee
Splunk Employee

Thanks for your reply!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...