Refine your search:

My environment consists of CheckPoint Provider1 MDS/CMA/CLM: I'm running a MDS (MultiDomainServer) with multiple customer environments (CMA). However, all log traffic is sent back to our central log repository (CLM). Question is: How should configure my splunk CheckPoint application to retrieve all customer logs???

asked 05 Jan '12, 12:39

jbsplunk's gravatar image

jbsplunk ♦
10.6k1625
accept rate: 48%


One Answer:

To retrieve CheckPoint logs from our CLM we did this:

  1. create the OPSEC application on the MDS
  2. push the OPSEC application to the CMA and CLM
  3. run the opsecpullcert using SSLCA against the MDS
  4. retrieve the SIC of the OPSEC application and CLM
  5. configure lea.conf using the OPSEC application and CLM SIC name
  6. configure lea.conf to pull logs from the CLM
  7. configure lea.conf to use auth_type SSLCA
link

answered 05 Jan '12, 13:30

Chubbybunny's gravatar image

Chubbybunny
1.3k28
accept rate: 72%

edited 01 May, 13:51

Thanks, these were exactly the steps I needed!

(05 Jan '12, 13:37) jbsplunk ♦

you Betcha!!!

(05 Jan '12, 13:38) Chubbybunny

In step 2. "push the OPSEC application to the CMA and CLM" should be revised to: "Install the database to the CMA"

*thanks for the correction Mahesh!!!

(15 Jun '12, 12:00) Chubbybunny
Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

Asked: 05 Jan '12, 12:39

Seen: 830 times

Last updated: 01 May, 13:51

Copyright © 2005-2012 Splunk Inc. All rights reserved.