I see it does not explicitly list 7.1 in Splunkbase. Does anyone have this running with 7.1.1?
Thanks!
Yes, is fully compatible.
The author is just late in updating his splunkbase entry. The very simplified app contains nothing that would be incompatible with v7.1 splunk, as is the case with most inputs/CIM-based apps. What do you say, @trustedsubject?
Should be compatible. As I understand it, AuditD logs are sent via syslog. Any field extractions are defined in the app, so the new version of Splunk should have nothing to do with it.
I agree with @MonkeyK