I noticed that when I downloaded the newest verison of Splunk Security Essentials 3.7.0, it is a SPL and not a TGZ like all of the other splunk apps are. We have it programmed when uploading this zipped file to take in TGZ and not SPL. Do I need to zip this as a TGZ? What's up with that?
Thanks!
From a Splunk-perspective, a file with a .spl extension is actually just a .tgz that has been renamed to indicate that the archive contains a Splunk add-on.
You don't need to do anything special with .spl files; they are supported in Splunk and you should be able to open them with common archiving programs.
It's still a tgz file; you can rename it from *.spl to *.tgz and use it directly.