Hello everyone,
My problem is as follows:
I need to install Splunk Soar on my home laboratory.
Now seeing that the versions are compatible with Centos7/8 which are deprecated, the moment I launch soar-installer or the soar-prepare-installer file, problems arise. Now since I have searched community and web but no luck.
Is there a possibility to install SOAR on ubuntu? Also it is true that Amazon Linux 2 and RHEL is recommended, but is it possible that there is no way to install SOAR on other linux distribution?
Thank you,
biwanari
Indeed, SOAR on-prem is in an awkward situation for OS support. SOAR on-prem only supports Amazon Linux 2, RHEL, or the end-of-support CENTOS.
The SOAR automation broker runs on Debian, but that only helps you if you are using the Cloud version of SOAR.
I believe there was some chatter in the #SOAR usergroup about adding support for 2 other CENTOS-related linux distros, but it's not there yet.
You probably could get SOAR running on a distro similar to CENTOS, but you'd have to spend more time tinkering to get it working.
Yes, finally by getting my hands dirty on RHEL8 I was able to install soar. I hope Splunk takes measures because next year rhel8 reaches EOL and that will become an issue to take the certification as well.
I read on reddit about people who modified the soar files to install it on centos-like systems, but it takes a lot of time.
Having said that I hope they take action because such a situation is not possible.
I hope this post will be read by people who have had the same problem as me so I can help them ae write to me on this post.
Greetings,
Andrew
@biwanari Can you help me with the steps of installation of Splunk Soar <Free Trial/UN-Privileged> in RHEL Version 9
Could you be more specific?
I suggest you to install on RHEL8 because SOAR does not officially support RHEL9.