Is this app compatible with the latest version of Splunk and Splunk UF? Is this intended to replace the need for barnyard2?
Hey there -
We're not officially supporting the Unified2 TA, as we've moved on from it and use Suricata now. That said, it should still work in the latest UF, as it relies on the system Python rather than Splunk's built-in Python. It was indeed intended to replace barnyard2.
If you try it with the newest UF and it doesn't work, we can provide some best effort help if you need it.
Hi mcmaster,
Does this parse Unified2 event_types, i.e. mpls_ID, vlan_ID, app_ID? Will it work with Python3?
Hey there -
We're not officially supporting the Unified2 TA, as we've moved on from it and use Suricata now. That said, it should still work in the latest UF, as it relies on the system Python rather than Splunk's built-in Python. It was indeed intended to replace barnyard2.
If you try it with the newest UF and it doesn't work, we can provide some best effort help if you need it.
Hi mcmaster,
Will this work with Python3? Does it parse unified2 event_types, i.e. mpls, vlan, appid?