I configured OPSEC LEA add-on on my Splunk server (ubuntu). Established a connection with Check Point management, but in manage connection, in "connection field" appears Never Connrcted. And no log indexed in Splunk.
you can try debugging the OPSEC input to determine if there are any obvious errors using this command:
/opt/splunk/bin/splunk cmd /opt/splunk/etc/apps/Splunk_TA_opseclea_linux22/bin/lea-loggrabber-debug.sh
however, the debug output is very verbose, so you may want to open a Support case for expert advice.
I recieve debug output. Where i can open support case?