All Apps and Add-ons

Support for Splunk Version 8

bennobog
New Member

Hi!

We're using this app in our test-Splunk environment which is running Splunk 7.3.2
We want to put this in our production environment, but that environment is running Splunk 8.0.1
I can see on the ThreatHunting app page it says max version 7.3

Will the app need an update to function on Splunk 8? If so, is it in the works?

Regards, Benjamin

0 Karma

bennobog
New Member

Kind of off-topic, but I'll try anyway:

We have separate roles on our splunk servers.
Some run as indexers, some run as search heads.

Would ThreatHunting work installed on a search head?

Regards, Benjamin

0 Karma

bennobog
New Member

Great, thanks Olaf!
It's great to hear you're still developing the app. It's a nice piece of kit 🙂

0 Karma

olafhartong
Engager

Thanks for answering this PaveIP.
Splunk 8 is supported. I’ll update the Splunkbase page accordingly.

I’m working on several updates but do not have a timeline on when they will be done.

0 Karma

PavelP
Motivator

Hello @bennobog,

according to the documentation, this app is maintained on GitHub > https://github.com/olafhartong/threathunting , so you can file an issue here: https://github.com/olafhartong/threathunting/issues to get the author's attention

The app doesn't contain any python code and it seems there are no other blocking features mentioned here : https://docs.splunk.com/Documentation/Splunk/8.0.3/Installation/AboutupgradingREADTHISFIRST

But anyway either wait for an answer from developer or test it in your test environment.

0 Karma
Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...