All Apps and Add-ons

Installation of SOAR on different linux version

biwanari
Explorer

Hello everyone,

My problem is as follows:

I need to install Splunk Soar on my home laboratory.
Now seeing that the versions are compatible with Centos7/8 which are deprecated, the moment I launch soar-installer or the soar-prepare-installer file, problems arise. Now since I have searched community and web but no luck.

Is there a possibility to install SOAR on ubuntu? Also it is true that Amazon Linux 2 and RHEL is recommended, but is it possible that there is no way to install SOAR on other linux distribution?

Thank you,
biwanari

Labels (2)
Tags (3)
0 Karma

marnall
Motivator

Indeed, SOAR on-prem is in an awkward situation for OS support. SOAR on-prem only supports Amazon Linux 2, RHEL, or the end-of-support CENTOS.

The SOAR automation broker runs on Debian, but that only helps you if you are using the Cloud version of SOAR.

I believe there was some chatter in the #SOAR usergroup about adding support for 2 other CENTOS-related linux distros, but it's not there yet.

You probably could get SOAR running on a distro similar to CENTOS, but you'd have to spend more time tinkering to get it working.

0 Karma

biwanari
Explorer

Yes, finally by getting my hands dirty on RHEL8 I was able to install soar. I hope Splunk takes measures because next year rhel8 reaches EOL and that will become an issue to take the certification as well.

I read on reddit about people who modified the soar files to install it on centos-like systems, but it takes a lot of time.

Having said that I hope they take action because such a situation is not possible.

I hope this post will be read by people who have had the same problem as me so I can help them ae write to me on this post.

Greetings,
Andrew

0 Karma

alwinhb
New Member

@biwanari  Can you help me with the steps of installation of Splunk Soar <Free Trial/UN-Privileged> in RHEL Version 9

0 Karma

biwanari
Explorer

Could you be more specific?

I suggest you to install on RHEL8 because SOAR does not officially support RHEL9.

0 Karma
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...