Propably event format for field transformations "outbound_interface_for_checkpoint" is incorrect and it should be "outbound_interface::$1"
Also fields extraction "opsec : REPORT-rule_for_opsec" refers to transform rule that doesn't exist.
Not a question, contact the App Author to report bugs/typos.
http://apps.splunk.com/app/1454/
- Check Contact info in the Bottom Right.
No worries, please accept this answer if it addressed your need. Thanks!
My appologies.