Getting Data In

Has anyone installed the Corelight App (and TA) onto a clustered Splunk setup

robnewman666
Path Finder

I am trying to setup the Corelight App for Zeek data on a clustered Splunk setup, but it seems the TA doesn't want to work along with the App.  The App is required to be installed onto the Search Head cluster and the TA is to be on the Indexers, as per the guidelines from Corelight. I am wondering if the install isn't suited to a clustered Splunk setup.

I am also having error codes for a Windows TA - but im not sure if this relates to this issue here.

Labels (1)
0 Karma

lznger88ncc
Engager

Hi, I am also having issues with the TA. Did you find a resolution to your issue?

0 Karma

robnewman666
Path Finder

As I recall, I think I made up my own TA to deal with the logs and also used some of the props.conf configs from the app which worked ok in the end for what I wanted it to do.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...