All Apps and Add-ons

OPSEC lea_loggrabber failed to run

ksirisawatdi_sp
Splunk Employee
Splunk Employee

My customer try OPSEC lea_loggrabber and getting error message saying that "Segmentation fault". Anyone having sillier issue before?alt text

Tags (1)
1 Solution

Chubbybunny
Splunk Employee
Splunk Employee

The lea_loggrabber client can encounter a "segmentation fault" for various reasons.
To gain a better understanding of the problem, you should elevate the OPSEC debugging level using the article below:
how-can-i-debug-my-lea-client-for-checkpoint

View solution in original post

mlogendra_splun
Splunk Employee
Splunk Employee

When the checkpoint add-on is trying to connect to the checkpoint server, it will try to resolve itself. When it is unable to do so, it will exit with a "segmentation fault" message.

Add a host entry with the hostname of Splunk server and its IP in /etc/hosts and the segmentation fault should go away.

0 Karma

jgedeon120
Contributor

If you are looking at getting logs from a Check Point you may want to take a look at this article. I'm also in the long process of creating a Check Point App for Splunk and it does use this method of getting the logs from the management server.

Splunking Check Point

0 Karma

Chubbybunny
Splunk Employee
Splunk Employee

The lea_loggrabber client can encounter a "segmentation fault" for various reasons.
To gain a better understanding of the problem, you should elevate the OPSEC debugging level using the article below:
how-can-i-debug-my-lea-client-for-checkpoint

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...