Hello all,
I have an issue setting up the LEA pull for Check Point logs. The only thing unusual in my environment, particularly given the errors about passAuth, is that I'm running the free version of Splunk.
I go through the installation process without issue, but when I hit the last step (providing the SIC name and the Entity SIC name), I click submit and get no response at all (no errors, no logs, etc.). I've tried restarting, tried going back and resubmitting the previous page (both of which work without an error message), and tried listing my OPSEC connectors which produces a /fail page.
When I search for the logs, I see a bunch of the following messages (seeming to roughly correlate to each time I clicked the submit button):
2013-07-22 08:25:13,491 ERROR [51ed4ed8e7ab62378c] <string>:449 - opsec_lea_ui_controller: unable to create scripted input for opsec config HomeProductionEvents - error: passAuth user does not exist: splunk-system-user
and then I also see a few of these messages, which seems to correlate with trying to view the existing connections:
2013-07-22 08:28:02,267 WARNING [51ed4f8203ad590b0c] <string>:115 - opsec_lea_ui_controller: problem retreiving opsec config HomeProductionEvents
Any ideas for how I could troubleshoot or resolve this?
... View more