I read both articles and performed the work that you stated. I still have no more logs than I did before. Again the CPFW admin states that the CP gui states that in the last 8 hrs they have 17million events and Splunk having all 5 inputs enabled shows only 5800 events for the past 24 hrs.
7/27/16
10:49:13.604 AM
2016-07-27 17:49:13,604 +0000 log_level=DEBUG, pid=86465, tid=Thread-131, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_sd" connection="wvdpclogsvr" data="smartdefense"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104311 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:13.599 AM
2016-07-27 17:49:13,599 +0000 log_level=DEBUG, pid=86465, tid=Thread-129, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_na" connection="wvdpclogsvr" data="non_audit"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104307 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:13.597 AM
2016-07-27 17:49:13,597 +0000 log_level=DEBUG, pid=86465, tid=Thread-127, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_vpn" connection="wvdpclogsvr" data="vpn"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104303 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:13.595 AM
2016-07-27 17:49:13,595 +0000 log_level=DEBUG, pid=86465, tid=Thread-125, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_fwe" connection="wvdpclogsvr" data="fw"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104299 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:13.593 AM
2016-07-27 17:49:13,593 +0000 log_level=DEBUG, pid=86465, tid=Thread-123, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_fwa" connection="wvdpclogsvr" data="audit"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104296 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:12.604 AM
2016-07-27 17:49:12,604 +0000 log_level=DEBUG, pid=86465, tid=Thread-131, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_sd" connection="wvdpclogsvr" data="smartdefense"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104311 parent_pid=86465, Sleeping 1 sec
host = splk-idx-05.wv.mentorg.com source = /opt/splunk/var/log/splunk/splunk_ta_checkpoint-opseclea_modinput.log sourcetype = opseclea:log:modinput
7/27/16
10:49:12.599 AM
2016-07-27 17:49:12,599 +0000 log_level=DEBUG, pid=86465, tid=Thread-129, file=ta_opseclea_data_collector.py, func_name=get_logs, code_line_no=62 | [input_name="internal_na" connection="wvdpclogsvr" data="non_audit"]log_level=3 file:lea_loggrabber.cpp func_name:main code_line_no:1107 :Current pid=104307 parent_pid=86465, Sleeping 1 sec
And this is all that the logs are showing me
... View more