Getting Data In

lea_loggrabber functionality

Wilf
Explorer

I am connecting to a Checkpoint Smart Manager
(SPLAT) using the "lea-loggrabber-splunk-linux-4x-42928" App.

I need to know how it requests the data.

In lea _new _session does it read in online mode and choose to start reading where it left off, say at position x in log file ID x. It needs to do this so I can be sure that it reads to the end of file of that log file and then begins at the start of the next file in the fw.logtrack file until it reached the end of the most recent log file.

This will ensure that if the link to the Checkpoint manager goes down at any time, so long as the Checkpoint log has not been deleted; Splunk will pick up at the end of the last session and catch up to the new events streaming in.
Hope you can help

Wilf
Tags (3)
1 Solution
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...