All Apps and Add-ons

What is the difference between the new OPSEC LEA app and the old one?

a212830
Champion

What's the difference between this one and the existing one? It appears that the functionality is the same - you've just put a admin gui in front of it. Still waiting on a persistent/real-time connection - not a script that wakes up every xx seconds.

0 Karma
1 Solution

araitz
Splunk Employee
Splunk Employee

The Splunk TA for Opsec LEA has been completely redesigned and reimplemented for vastly improved speed, scale and reliablity, much better configurability and usability, a convenient UI, enhanced support for the most popular Checkpoint platforms including Provider-1/CMA R70/75.1/75.4, complete install and configuration documentation, support for audit logs and no-resolve mode, improved debugging, several critical bug fixes, a new knowledge layer for the data collected from Firewall/CMA, and a lot more.

It is too bad that the standard polling impletementation does not work for your use case. If you could explain in detail why persistent connections are better than polling for you, we will add it to your existing enhancement request for this feature and consider it for a future version of the product.

View solution in original post

araitz
Splunk Employee
Splunk Employee

The Splunk TA for Opsec LEA has been completely redesigned and reimplemented for vastly improved speed, scale and reliablity, much better configurability and usability, a convenient UI, enhanced support for the most popular Checkpoint platforms including Provider-1/CMA R70/75.1/75.4, complete install and configuration documentation, support for audit logs and no-resolve mode, improved debugging, several critical bug fixes, a new knowledge layer for the data collected from Firewall/CMA, and a lot more.

It is too bad that the standard polling impletementation does not work for your use case. If you could explain in detail why persistent connections are better than polling for you, we will add it to your existing enhancement request for this feature and consider it for a future version of the product.

a212830
Champion

Thanks for the info. The checkpoint data is used for security purposes, which requires a real-time, persistent feed, not a script that is going to wake up every xx seconds.

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...