Getting Data In

Options in lea-loggrabber app

Mahieu
Communicator

Hi there,

I'm using the old lea-loggrabber app for collecting my Checkpoint logs (this one http://wiki.splunk.com/Community:Configure_OPSEC_LEA_input).
Is there a way to disable name resolution in there ?
I've seen that it's a simple option in the new Splunk Add-on for Check Point OPSEC LEA.

I might migrate to the new app but I need to work on it as I've made a few changes to my scripts to support Splunk HA.
I have two indexers in a cluster and I can't have both running the script which would mean indexing the logs twice.

Thanks in advance.

M.

duberich
New Member

You can turn off name resolution with a patched binary as referenced in http://answers.splunk.com/answers/23975/check-point-object-name-resolution.html

We usually setup a separate heavy forwarder for data collection using a pull for things like checkpoint, mcafee, sourcefire, dbcollect, etc.

Regards,
--RIch

0 Karma

Mahieu
Communicator

Looks interesting, do you know where I can get this patched version ?
Thanks in advance.

Mat

0 Karma

duberich
New Member

Should be able to get it through support.

--Rich

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...