All Apps and Add-ons

Compatibility with Splunk enterprise 7.1

gpolyzoi
Engager

Aruba ClearPass App is not compatible with Splunk version 7.1.x Please let us know what will be the estimate time for releasing of compatible versions of these apps.

0 Karma

sphadnis
Path Finder

Has this app been tested for functionality with Splunk 7.2 yet? the App splunkbase page mentions compatibility only till 7.1

0 Karma

dannyjump
Engager

I've just had QA take a look at 7.x.

We've added 7.1 to the list of compatibility versions, 7.2 looks OK so far and I hope to get a thumbs-up early next week.

michaelakinneyn
Engager

When going to v7.2.x+ from 7.1.x You will want to comment out the below fields, that is in the default/props.conf that will not show up as a field extraction.

This is the only anomaly so far that has come up after upgrading to v7.2.3 from v7.1.0

$splunk_homedir/splunk/etc/apps/ClearPassOnSplunk_2/default/props.conf

Field Aliases

commenting out remaining aliases to isolate missing field extractions

FIELDALIAS-cppm-24 = framed_ip_address AS ip_address
FIELDALIAS-cppm-016 = username as user_name
FIELDALIAS-cppm-acctnasip = nas_ip_address AS nas_ip
FIELDALIAS-cppm-019 = nad_ip AS nas_ip
FIELDALIAS-cppm-910 = host_mac AS mac_address
FIELDALIAS-cppm-911 = end_host_id AS mac_address
FIELDALIAS-cppm-911 = mac_address AS end_host_id

FIELDALIAS-cppm-host = ClearPass_Server AS host

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...