Getting Data In

lea_loggrabber functionality

Wilf
Explorer

I am connecting to a Checkpoint Smart Manager
(SPLAT) using the "lea-loggrabber-splunk-linux-4x-42928" App.

I need to know how it requests the data.

In lea _new _session does it read in online mode and choose to start reading where it left off, say at position x in log file ID x. It needs to do this so I can be sure that it reads to the end of file of that log file and then begins at the start of the next file in the fw.logtrack file until it reached the end of the most recent log file.

This will ensure that if the link to the Checkpoint manager goes down at any time, so long as the Checkpoint log has not been deleted; Splunk will pick up at the end of the last session and catch up to the new events streaming in.
Hope you can help

Wilf
Tags (3)
1 Solution
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Supercharging Windows Security Detection Performance: Introducing Hybrid Field ...

Windows event logs—from Security auditing and Sysmon to PowerShell script blocks—form the operational backbone ...

Ditch the Manual Grind: Building AI Agents with Splunk

Ditch the Manual Grind: Building AI Agents with Splunk Let’s be real: your team’s time is being eaten alive. ...

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...