Hi everyone,
I've installed the Splunk Add-on for Checkpoint OPSEC LEA v.3.1.0 on Splunk Enterprise v.6.2.4.
The version of the firewall is R77.30, but on the requirements I can see the upper version indicated i R77.
Does anyone know if version R77.30 is also supported?
On the opsec_watchdog.log file I always have these three lines:
2015-08-07 15:48:51,821 INFO 22457 140600047077184 Starting exec: ['./lea_loggrabber', '--configentity', 'SplunkLEA', '--appname', 'Splunk_TA_opseclea_linux22']
2015-08-07 15:48:53,073 INFO 22457 140600047077184 got ret code 1
2015-08-07 15:48:54,074 INFO 22457 140600047077184 process crashed (1), restarting
... View more