All Apps and Add-ons

Does the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80?

tallan
Engager

Will the Splunk Add-on for Check Point OPSEC LEA work with Checkpoint R80? We are in the process of doing an early upgrade on all Checkpoint managers and log servers to R80. The older version of Checkpoint that we were on, R77, is currently supported by the OPSEC LEA add-on and has functioned properly since installation, but I do not see any information or release dates for support of R80. Has anyone tried R80 and the OPSEC LEA add-on?

0 Karma
1 Solution

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

View solution in original post

FrankVl
Ultra Champion

Given that R80 supports syslog forwarding, you might want to take a look a that. Could make your checkpoint data collection a lot easier. You'd need to create a custom TA for it, since the official add-on does not support the syslog format, but apart from the basic field extractions, you can re-use a lot of logic from the original TA.

0 Karma

tonisaprano
New Member

But starting with version 4.0.0 release notes tell that Add-on supports R80. (vendor Products Check Point OPSEC LEA R76, R77, R80). Actually has anybody tried R80 and the OPSEC LEA add-on?

0 Karma

larmesto
Path Finder

Splunk Add-on for Check Point OPSEC LEA does not support the r80 release of Check Point. The add-on requires 77.3 or earlier. regards

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...