All Apps and Add-ons

Do I need to install the Splunk Add-on for Check Point OPSEC LEA on both search heads and indexers running Splunk 6.4.1?

pinVie
Path Finder

Hi,

I am currently working on a 6.4.1 environment and I need to use the Splunk Add-on for Check Point OPSEC LEA, but this is only available for 6.3.x.
What I did for now is to set up a 6.3.x Heavy Forwarder and installed the OPSEC Add-on there -> everything fine.

But according to the documentation, I have to install it on the Search heads and Indexers as well. Do I have to downgrade them all, or can I just install the app? I assume indexers and search heads only use parts of the app that should work on Splunk 6.4.1 as well - like props.conf, transforms.conf, lookups, ... Is this correct?

Thank you !

0 Karma
1 Solution

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

View solution in original post

0 Karma

javiergn
Super Champion

Keep in mind a new version of the OPSEC LEA app should be released any time soon so might want to wait a few weeks.
See this: https://answers.splunk.com/answers/407882/will-the-opsec-lea-add-on-be-updated-to-support-sp.html

0 Karma

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

0 Karma

pinVie
Path Finder

That's what i wanted to hear 🙂 thx

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...