Splunk Search

Splunk Add-on for Check Point OPSEC LEA Linux: Why am I getting error "Client could not choose an authentication method for service lea"?

rodrigorsilva
Communicator

Hello everyone,

I'm trying to set up a manage CheckPoint OPSEC performed using the procedure as the documentation:

http://docs.splunk.com/Documentation/OPSEC-LEA/2.1.1/Install/ConfiguretheLEAclient#Configure_using_t...

This time to run tests with the add-on:

/opt/splunk/bin/splunk cmd /opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh

I get the following message:

DEBUG: OPSEC_SESSION_END_HANDLER called
ERROR: SIC ERROR 119 - SIC Error for lea: Client could not choose an authentication method for service lea

Would anyone have a clue what I might be missing?

Thanks to all

Rodrigo Ribeiro

1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

can you post your opsec_entity_sic_name and opsec_sic_name details in opsec.conf?
SIC 119 is generally caused by misconfigured settings in this file.

View solution in original post

Chubbybunny
Splunk Employee
Splunk Employee

can you post your opsec_entity_sic_name and opsec_sic_name details in opsec.conf?
SIC 119 is generally caused by misconfigured settings in this file.

rodrigorsilva
Communicator

It worked, the file you indicated has a parameter:

opsec_sslca_file = ../certs/SplunkLEA.p12

When I ran the push the files were stored in:

/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/opsec-tools

Basically moved the files to the location pointed to:

[root@LABO2 opsec-tools]# pwd
/opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/opsec-tools
[root@LABO2 opsec-tools]# cp *.p12 ../certs/

In a way your tip led me to the exact point, thank you.

Rodrigo Ribeiro

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...