All Apps and Add-ons

Why am I having issues getting Splunk OPSEC-LEA authentication in Splunk Add-on for Check Point OPSEC LEA?

tiagofbmm
Influencer

Hello

I'm facing an issue connecting to a Primary OPSEC-LEA server:

Client Could not choose an authentication method for service lea. 

Any ideas what would solve it?

0 Karma
1 Solution

milesbrennan
Path Finder

There is a current issue with an updated glibc library if you're on Linux, this was my workaround:

First - yum downgrade glibc glibc-common libgcc

Dependencies Resolved

==============================================================================================================

Package Arch Version Repository Size

Downgrading:
glibc i686 2.17-196.el7_4.2 rhel-7-server-rpms 4.2 M
glibc x86_64 2.17-196.el7_4.2 rhel-7-server-rpms 3.6 M
glibc-common x86_64 2.17-196.el7_4.2 rhel-7-server-rpms 11 M
libgcc i686 4.8.5-28.el7 rhel-7-server-rpms 108 k
libgcc x86_64 4.8.5-28.el7 rhel-7-server-rpms 101 k

Transaction Summary

Downgrade 5 Packages

Second - service splunk restart

Third - Goto OPSEC Addon and rejoin all CP management servers

Fourth (validation) - index=firewall sourcetype=opsec | stats count by host

Fifth - yum upgrade

View solution in original post

0 Karma

milesbrennan
Path Finder

There is a current issue with an updated glibc library if you're on Linux, this was my workaround:

First - yum downgrade glibc glibc-common libgcc

Dependencies Resolved

==============================================================================================================

Package Arch Version Repository Size

Downgrading:
glibc i686 2.17-196.el7_4.2 rhel-7-server-rpms 4.2 M
glibc x86_64 2.17-196.el7_4.2 rhel-7-server-rpms 3.6 M
glibc-common x86_64 2.17-196.el7_4.2 rhel-7-server-rpms 11 M
libgcc i686 4.8.5-28.el7 rhel-7-server-rpms 108 k
libgcc x86_64 4.8.5-28.el7 rhel-7-server-rpms 101 k

Transaction Summary

Downgrade 5 Packages

Second - service splunk restart

Third - Goto OPSEC Addon and rejoin all CP management servers

Fourth (validation) - index=firewall sourcetype=opsec | stats count by host

Fifth - yum upgrade

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...