Getting Data In

lea_loggrabber functionality


I am connecting to a Checkpoint Smart Manager
(SPLAT) using the "lea-loggrabber-splunk-linux-4x-42928" App.

I need to know how it requests the data.

In lea _new _session does it read in online mode and choose to start reading where it left off, say at position x in log file ID x. It needs to do this so I can be sure that it reads to the end of file of that log file and then begins at the start of the next file in the fw.logtrack file until it reached the end of the most recent log file.

This will ensure that if the link to the Checkpoint manager goes down at any time, so long as the Checkpoint log has not been deleted; Splunk will pick up at the end of the last session and catch up to the new events streaming in.
Hope you can help

Tags (3)
1 Solution
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...