Splunk Search

Splunk Add-on for Check Point OPSEC LEA Linux: Why am I getting error "Client could not choose an authentication method for service lea"?

rodrigorsilva
Communicator

Hello everyone,

I'm trying to set up a manage CheckPoint OPSEC performed using the procedure as the documentation:

http://docs.splunk.com/Documentation/OPSEC-LEA/2.1.1/Install/ConfiguretheLEAclient#Configure_using_t...

This time to run tests with the add-on:

/opt/splunk/bin/splunk cmd /opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh

I get the following message:

DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

Would anyone have a clue what I might be missing?

Thanks to all

Rodrigo Ribeiro

1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

can you post your opsec_entity_sic_name and opsec_sic_name details in opsec.conf?
SIC 119 is generally caused by misconfigured settings in this file.

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

can you post your opsec_entity_sic_name and opsec_sic_name details in opsec.conf?
SIC 119 is generally caused by misconfigured settings in this file.

rodrigorsilva
Communicator

It worked, the file you indicated has a parameter:

opsec_sslca_file = ../certs/SplunkLEA.p12

When I ran the push the files were stored in:

/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/opsec-tools

Basically moved the files to the location pointed to:

[root@LABO2 opsec-tools]# pwd
/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/opsec-tools
[root@LABO2 opsec-tools]# cp *.p12 ../certs/

In a way your tip led me to the exact point, thank you.

Rodrigo Ribeiro

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...