Activity Feed
- Karma Re: Checkpoint LEA pointer is reset, events are re-indexed for hexx. 06-05-2020 12:46 AM
- Karma Re: Checkpoint LEA pointer is reset, events are re-indexed for lmyrefelt. 06-05-2020 12:46 AM
- Karma Re: How do I find the DN of the Checkpoint log manager object in Checkpoint R75.40? for dart. 06-05-2020 12:46 AM
- Karma Re: Frequency lea updates pointer file for sdwilkerson. 06-05-2020 12:46 AM
- Karma Re: Opinions on Index Optimization for tgiles. 06-05-2020 12:46 AM
- Got Karma for Checkpoint LEA pointer is reset, events are re-indexed. 06-05-2020 12:46 AM
- Got Karma for Checkpoint LEA pointer is reset, events are re-indexed. 06-05-2020 12:46 AM
- Got Karma for Re: Firewall checkpoint for windows 8. 06-05-2020 12:46 AM
- Got Karma for Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Re: Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Re: Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Re: Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Got Karma for Re: Checkpoint R75.40 and OPSEC LEA. 06-05-2020 12:46 AM
- Karma Re: Can't route forwarded data to different index? for dwaddle. 06-05-2020 12:45 AM
- Posted Re: Firewall checkpoint for windows 8 on Getting Data In. 09-24-2012 02:32 PM
- Posted Re: Checkpoint LEA pointer is reset, events are re-indexed on Getting Data In. 07-31-2012 01:26 AM
- Posted Re: Checkpoint LEA pointer is reset, events are re-indexed on Getting Data In. 07-30-2012 02:32 PM
- Posted Checkpoint LEA pointer is reset, events are re-indexed on Getting Data In. 07-30-2012 10:15 AM
Topics I've Started
Subject | Karma | Author | Latest Post |
---|---|---|---|
2 | |||
3 |
09-24-2012
02:32 PM
1 Karma
I don't think you can using the Splunk-supplied OPSEC LEA for CheckPoint app as it only works under Linux or Solaris. You'd need a separate Linux or Solaris Splunk instance running the Checkpoint app and forward the logs to your Windows Splunk instance. I use this setup and it works ok.
If you can't run an instance on anything but Windows for some reason, then the solution outlined in this post might help. I've not tried this method, though, so I can't comment on how well it works.
... View more
07-31-2012
01:26 AM
OK, I'll try increasing the time between polls and see if that makes a difference. Thanks for the tip!
... View more
07-30-2012
02:32 PM
OK, thanks for that. I'm glad that it's known about.
Do you know whether there is any way to work around the problem, and when it might be fixed?
... View more
07-30-2012
10:15 AM
2 Karma
I've recently set up LEA-LogGrabber, which is working fine from a communication point of view - the logs are being successfully retrieved from the Checkpoint Manager and fed into Splunk. However, I've noticed that I seem to be getting identical log entries repeated in my Splunk logs. This means that searches tend to return more data than necessary and also it's using up more of my daily Splunk license than it should.
It looks like the reference pointer in the file "lea_log_rec_num.cache" in $SPLUNK_HOME/etc/apps/lea-loggrabber-splunk/bin is somehow getting reset back to 0 regularly and therefore the whole logfile is being reread into Splunk on a regular basis.
For example, see the repeated commands below:
/opt/splunk/etc/apps/lea-loggrabber-splunk/bin$ cat lea_log_rec_num.cache
13271
/opt/splunk/etc/apps/lea-loggrabber-splunk/bin$ cat lea_log_rec_num.cache
13271
/opt/splunk/etc/apps/lea-loggrabber-splunk/bin$ cat lea_log_rec_num.cache
0
/opt/splunk/etc/apps/lea-loggrabber-splunk/bin$ cat lea_log_rec_num.cache
13271
Does anyone know what could be causing this behaviour and how to stop it from happening?
... View more
- Tags:
- checkpoint
07-20-2012
08:37 AM
Thanks for that - the description on the third-party site is very clear.
... View more
07-06-2012
12:19 AM
4 Karma
Just to complete the thread, I've now solved the problem. It turned out to not be a problem with either Splunk or Checkpoint, but was a routing issue in the network. The routing has now been fixed and the OPSEC components are now communicating.
... View more
07-03-2012
12:53 AM
3 Karma
I've been trying to get the OPSEC LEA loggrabber working with my Splunk (v4.3.2) and Checkpoint (R75.40). I've followed the instructions in OPSEC LEA for Checkpoint. I've installed the app on the forwarder successfully and have set up the OPSEC object in Checkpoint, along with the bits to enable the LEA server. However, when I try to retrieve the OPSEC certificate using opsec_pull_cert this fails. I can see in the Checkpoint logs that the connection is being attempted, but the Checkpoint server doesn't seem to respond to the certificate request.
Can anyone tell me if I've missed something? Do I need to enable something in Checkpoint to tell it to respond to certificate downloads or something like that?
... View more
- Tags:
- checkpoint
- opsec