- Local User Groups
Are you after anything in particular? As the options you select on the OPSEC configuration may differ per product.
Or are you after a quick how to setup an OPSEC configuration?
As Kosin Usuwanthim has advised the 3rd party should have a guide on how to integrate their product with Check Point.
Yes, we are using ArcSight.
But the actual issue that we are facing is that "User" field is shown as "Confidential" in logs (Clear connection is configured).
I also gone through sk101570 (3rd Scenario) which is related to our issue. I hope by following the given procedure will solve this issue. Kindly suggest...
Reference : sk101570
Within your OPSEC configuration do you have the LEA configuration settings set to "Hide all confidential log fields"? This will cause what you are seeing.
if you can post your OPSEC configuration we can take a look and advise as necessary.
As stated in earlier comment , the connection type configured is "clear" in ArcSight. I believe that we need not to create an OPSEC application for clear connection.
Sounds like you're on the right track as far as the LEA options. Let us know how it works out for you.
I had performed the same :
But the issue is still persisting. "Target User Name " filed in logs received in ArcSight is still showing as ***confidential ***.
More over the Management Server is running on GAIA Windows OS R77.30.
Dameon Welch-Abernathy Kindly suggest.