All Apps and Add-ons

Do I need to install the Splunk Add-on for Check Point OPSEC LEA on both search heads and indexers running Splunk 6.4.1?

pinVie
Path Finder

Hi,

I am currently working on a 6.4.1 environment and I need to use the Splunk Add-on for Check Point OPSEC LEA, but this is only available for 6.3.x.
What I did for now is to set up a 6.3.x Heavy Forwarder and installed the OPSEC Add-on there -> everything fine.

But according to the documentation, I have to install it on the Search heads and Indexers as well. Do I have to downgrade them all, or can I just install the app? I assume indexers and search heads only use parts of the app that should work on Splunk 6.4.1 as well - like props.conf, transforms.conf, lookups, ... Is this correct?

Thank you !

0 Karma
1 Solution

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

View solution in original post

0 Karma

javiergn
Super Champion

Keep in mind a new version of the OPSEC LEA app should be released any time soon so might want to wait a few weeks.
See this: https://answers.splunk.com/answers/407882/will-the-opsec-lea-add-on-be-updated-to-support-sp.html

0 Karma

jgedeon120
Contributor

You should be fine installing the TA on 6.4 for the field extractions.

0 Karma

pinVie
Path Finder

That's what i wanted to hear 🙂 thx

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...