Getting Data In

lea_loggrabber functionality

Wilf
Explorer

I am connecting to a Checkpoint Smart Manager
(SPLAT) using the "lea-loggrabber-splunk-linux-4x-42928" App.

I need to know how it requests the data.

In lea _new _session does it read in online mode and choose to start reading where it left off, say at position x in log file ID x. It needs to do this so I can be sure that it reads to the end of file of that log file and then begins at the start of the next file in the fw.logtrack file until it reached the end of the most recent log file.

This will ensure that if the link to the Checkpoint manager goes down at any time, so long as the Checkpoint log has not been deleted; Splunk will pick up at the end of the last session and catch up to the new events streaming in.
Hope you can help

Wilf
Tags (3)
1 Solution
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...