All Apps and Add-ons

Installation of SOAR on different linux version

biwanari
Explorer

Hello everyone,

My problem is as follows:

I need to install Splunk Soar on my home laboratory.
Now seeing that the versions are compatible with Centos7/8 which are deprecated, the moment I launch soar-installer or the soar-prepare-installer file, problems arise. Now since I have searched community and web but no luck.

Is there a possibility to install SOAR on ubuntu? Also it is true that Amazon Linux 2 and RHEL is recommended, but is it possible that there is no way to install SOAR on other linux distribution?

Thank you,
biwanari

Labels (2)
Tags (3)
0 Karma

marnall
Motivator

Indeed, SOAR on-prem is in an awkward situation for OS support. SOAR on-prem only supports Amazon Linux 2, RHEL, or the end-of-support CENTOS.

The SOAR automation broker runs on Debian, but that only helps you if you are using the Cloud version of SOAR.

I believe there was some chatter in the #SOAR usergroup about adding support for 2 other CENTOS-related linux distros, but it's not there yet.

You probably could get SOAR running on a distro similar to CENTOS, but you'd have to spend more time tinkering to get it working.

0 Karma

biwanari
Explorer

Yes, finally by getting my hands dirty on RHEL8 I was able to install soar. I hope Splunk takes measures because next year rhel8 reaches EOL and that will become an issue to take the certification as well.

I read on reddit about people who modified the soar files to install it on centos-like systems, but it takes a lot of time.

Having said that I hope they take action because such a situation is not possible.

I hope this post will be read by people who have had the same problem as me so I can help them ae write to me on this post.

Greetings,
Andrew

0 Karma

alwinhb
New Member

@biwanari  Can you help me with the steps of installation of Splunk Soar <Free Trial/UN-Privileged> in RHEL Version 9

0 Karma

biwanari
Explorer

Could you be more specific?

I suggest you to install on RHEL8 because SOAR does not officially support RHEL9.

0 Karma
Get Updates on the Splunk Community!

Fueling your curiosity with new Splunk ILT and eLearning courses

At Splunk Education, we’re driven by curiosity—both ours and yours! That’s why we’re committed to delivering ...

Splunk AI Assistant for SPL 1.1.0 | Now Personalized to Your Environment for Greater ...

Splunk AI Assistant for SPL has transformed how users interact with Splunk, making it easier than ever to ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...