All Apps and Add-ons

Support for Splunk Version 8

bennobog
New Member

Hi!

We're using this app in our test-Splunk environment which is running Splunk 7.3.2
We want to put this in our production environment, but that environment is running Splunk 8.0.1
I can see on the ThreatHunting app page it says max version 7.3

Will the app need an update to function on Splunk 8? If so, is it in the works?

Regards, Benjamin

0 Karma

bennobog
New Member

Kind of off-topic, but I'll try anyway:

We have separate roles on our splunk servers.
Some run as indexers, some run as search heads.

Would ThreatHunting work installed on a search head?

Regards, Benjamin

0 Karma

bennobog
New Member

Great, thanks Olaf!
It's great to hear you're still developing the app. It's a nice piece of kit 🙂

0 Karma

olafhartong
Engager

Thanks for answering this PaveIP.
Splunk 8 is supported. I’ll update the Splunkbase page accordingly.

I’m working on several updates but do not have a timeline on when they will be done.

0 Karma

PavelP
Motivator

Hello @bennobog,

according to the documentation, this app is maintained on GitHub > https://github.com/olafhartong/threathunting , so you can file an issue here: https://github.com/olafhartong/threathunting/issues to get the author's attention

The app doesn't contain any python code and it seems there are no other blocking features mentioned here : https://docs.splunk.com/Documentation/Splunk/8.0.3/Installation/AboutupgradingREADTHISFIRST

But anyway either wait for an answer from developer or test it in your test environment.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...