All Apps and Add-ons

Does the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80?

tallan
Engager

Will the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80? We are in the process of doing an early upgrade on all Checkpoint managers and log servers to R80. The older version of Checkpoint that we were on, R77, is currently supported by the OPSEC LEA add-on and has functioned properly since installation, but I do not see any information or release dates for support of R80. Has anyone tried R80 and the OPSEC LEA add-on?

0 Karma
1 Solution

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

View solution in original post

FrankVl
Ultra Champion

Given that R80 supports syslog forwarding, you might want to take a look a that. Could make your checkpoint data collection a lot easier. You'd need to create a custom TA for it, since the official add-on does not support the syslog format, but apart from the basic field extractions, you can re-use a lot of logic from the original TA.

0 Karma

tonisaprano
New Member

But starting with version 4.0.0 release notes tell that Add-on supports R80. (vendor Products Check Point OPSEC LEA R76, R77, R80). Actually has anybody tried R80 and the OPSEC LEA add-on?

0 Karma

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...