Hi!
We're using this app in our test-Splunk environment which is running Splunk 7.3.2
We want to put this in our production environment, but that environment is running Splunk 8.0.1
I can see on the ThreatHunting app page it says max version 7.3
Will the app need an update to function on Splunk 8? If so, is it in the works?
Regards, Benjamin
Kind of off-topic, but I'll try anyway:
We have separate roles on our splunk servers.
Some run as indexers, some run as search heads.
Would ThreatHunting work installed on a search head?
Regards, Benjamin
Great, thanks Olaf!
It's great to hear you're still developing the app. It's a nice piece of kit 🙂
Thanks for answering this PaveIP.
Splunk 8 is supported. I’ll update the Splunkbase page accordingly.
I’m working on several updates but do not have a timeline on when they will be done.
Hello @bennobog,
according to the documentation, this app is maintained on GitHub > https://github.com/olafhartong/threathunting , so you can file an issue here: https://github.com/olafhartong/threathunting/issues to get the author's attention
The app doesn't contain any python code and it seems there are no other blocking features mentioned here : https://docs.splunk.com/Documentation/Splunk/8.0.3/Installation/AboutupgradingREADTHISFIRST
But anyway either wait for an answer from developer or test it in your test environment.