All Apps and Add-ons

Splunk Security Essentials 3.7.0 a SPL and not a TGZ?

ggvaca
Explorer

I noticed that when I downloaded the newest verison of Splunk Security Essentials 3.7.0, it is a SPL and not a TGZ like all of the other splunk apps are. We have it programmed when uploading this zipped file to take in TGZ and not SPL. Do I need to zip this as a TGZ? What's up with that?

Thanks!

Labels (2)
0 Karma

Tom_Lundie
Contributor

From a Splunk-perspective, a file with a .spl extension is actually just a .tgz that has been renamed to indicate that the archive contains a Splunk add-on.

You don't need to do anything special with .spl files; they are supported in Splunk and you should be able to open them with common archiving programs.

0 Karma

ChrisG
Splunk Employee
Splunk Employee

It's still a tgz file; you can rename it from *.spl to *.tgz and use it directly.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...