Getting Data In

Splunk Checkpoint FW grabber collecting more logs than the one of the logserver

theouhuios
Motivator

I have a strange case where we see more logs in Splunk from the Checkpoint App than the ones in the Checkpoint log server itself. I did check for duplicates but even then we still see that Splunk has about 15-20% more logs than the checkpoint Server. We are running it on online mode.

We did have few issues with Checkpoint and Splunk has asked us to switch the THP setting off which we are working with the Unix team to see if its okay with them.

Any ideas? has anyone seen this issue before?

Tags (1)
0 Karma

matthieu_araman
Communicator

Hello,

I think what you are seen is that the same log is updated in checkpoint -> still one log in checkpoint as the log server can update directly a log entry afterwards.
But as you already collected it, you have two different logs in splunk.

example :
you've got a connection opening -> one log
the connection close and you've got accounting checked in checkpoint -> checkpoint update only the bytes column but you may see another log when collecting remotely.

there's also a log grace setting in Checkpoint but I think it should be transparent seen from splunk (ie you only see one log if the event is the same for the grace period which is by default 62s I think)

So I would say it's a feature.

You could try collecting with a delay to see it change the percentage.

theouhuios
Motivator

Thanks for the answer. We don't have this issue now. This ticket is old.. about a year old.

0 Karma

mbenwell
Communicator

Hi @theouhuios how did you solve this?

0 Karma

theouhuios
Motivator

We changed the lea-loggrabber.sh script. This was suggested by Splunk as an unoffical answer. It worked for us. It might work for you too.

Changes we did were for the last line

#$SPLUNK_HOME/bin/splunk cmd python ./watchdog.py --restartlimit 10 --splunkpid $PPID --sipid $$ ./lea_loggrabber "$@" --appname $app_name
./lea_loggrabber "$@" --appname $app_name
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...