All Apps and Add-ons

Installation of SOAR on different linux version

biwanari
Explorer

Hello everyone,

My problem is as follows:

I need to install Splunk Soar on my home laboratory.
Now seeing that the versions are compatible with Centos7/8 which are deprecated, the moment I launch soar-installer or the soar-prepare-installer file, problems arise. Now since I have searched community and web but no luck.

Is there a possibility to install SOAR on ubuntu? Also it is true that Amazon Linux 2 and RHEL is recommended, but is it possible that there is no way to install SOAR on other linux distribution?

Thank you,
biwanari

Labels (2)
Tags (3)
0 Karma

marnall
Motivator

Indeed, SOAR on-prem is in an awkward situation for OS support. SOAR on-prem only supports Amazon Linux 2, RHEL, or the end-of-support CENTOS.

The SOAR automation broker runs on Debian, but that only helps you if you are using the Cloud version of SOAR.

I believe there was some chatter in the #SOAR usergroup about adding support for 2 other CENTOS-related linux distros, but it's not there yet.

You probably could get SOAR running on a distro similar to CENTOS, but you'd have to spend more time tinkering to get it working.

0 Karma

biwanari
Explorer

Yes, finally by getting my hands dirty on RHEL8 I was able to install soar. I hope Splunk takes measures because next year rhel8 reaches EOL and that will become an issue to take the certification as well.

I read on reddit about people who modified the soar files to install it on centos-like systems, but it takes a lot of time.

Having said that I hope they take action because such a situation is not possible.

I hope this post will be read by people who have had the same problem as me so I can help them ae write to me on this post.

Greetings,
Andrew

0 Karma

alwinhb
New Member

@biwanari  Can you help me with the steps of installation of Splunk Soar <Free Trial/UN-Privileged> in RHEL Version 9

0 Karma

biwanari
Explorer

Could you be more specific?

I suggest you to install on RHEL8 because SOAR does not officially support RHEL9.

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...