I have an old version of Red Hat Linux 9 with snare installed. What version of splunk can I use to process the data caputed by snare?
Red Hat Linux 9 hit it's end of life in 2004. No modern software is guaranteed to work with an OS that old. See http://en.wikipedia.org/wiki/Red_Hat_Linux
You should be able to simply open a TCP or UDP port on the Splunk server and collect the data directly from Snare. This will work with any version of Splunk but its recommended that you use the latest release at the time of this post: 4.1.3