Hi,
I'm trying to update the Palo Alto App for Splunk but seems like it does not work:
# ./splunk install app /home/balbano/SplunkforPaloAltoNetworks.zip -update 1
Splunk username: $user
Password:
An error occurred:
file could not be opened successfully
Based on my reading looks like Splunk does not like ZIP files.
If that is the case how do I update to the new Palo Alto App?
Any help would be great.
Thanks.
Brian
hello Brian,
please extract the zip file and copy its contents to the $SPLUNK_HOME/etc/apps/
if you have an existing install of the Splunk for Palo Alto App, please backup any files that you may have modified e.g. your inputs.conf file.
more detailed installation instructions are in the README file in the zip.
cheers,
monzy