All Apps and Add-ons

Splunk Add-on for Check point OPSEC LEA Linux 3.0.0: Why do I keep getting a "Reconnecting to Splunk server" every time I try to make a new connection?

svclee
Engager

I have installed the v3.0 app on my Splunk indexer and when going to the APP to make a new connection, I get the below pop-up every time:

Reconnecting to Splunk server
Your network connection may have been lost or Splunk server may be down.

Is there a fix to this?
I have manually created a connection, but does not seem to be pulling logs.

0 Karma
1 Solution

svclee
Engager

I have misconfigured the the sic entity name.
Once we ran the lea debug, and found the right sic name, we updated the opsec.conf then restarted.
After restarting, all events are now available for search

View solution in original post

0 Karma

svclee
Engager

I have misconfigured the the sic entity name.
Once we ran the lea debug, and found the right sic name, we updated the opsec.conf then restarted.
After restarting, all events are now available for search

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

what does it say when you look at the logs?

index=_internal source=*Splunk_TA_opseclea*
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...