All Apps and Add-ons

Do I need to install the Splunk Add-on for Check Point OPSEC LEA on both search heads and indexers running Splunk 6.4.1?

pinVie
Path Finder

Hi,

I am currently working on a 6.4.1 environment and I need to use the Splunk Add-on for Check Point OPSEC LEA, but this is only available for 6.3.x.
What I did for now is to set up a 6.3.x Heavy Forwarder and installed the OPSEC Add-on there -> everything fine.

But according to the documentation, I have to install it on the Search heads and Indexers as well. Do I have to downgrade them all, or can I just install the app? I assume indexers and search heads only use parts of the app that should work on Splunk 6.4.1 as well - like props.conf, transforms.conf, lookups, ... Is this correct?

Thank you !

0 Karma
1 Solution

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

View solution in original post

0 Karma

javiergn
Super Champion

Keep in mind a new version of the OPSEC LEA app should be released any time soon so might want to wait a few weeks.
See this: https://answers.splunk.com/answers/407882/will-the-opsec-lea-add-on-be-updated-to-support-sp.html

0 Karma

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

0 Karma

pinVie
Path Finder

That's what i wanted to hear 🙂 thx

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...