Getting Data In

Looking for solutions for Linux/Unix Auditing?

kymenope
Explorer

Fairly new Splunk user here looking for Linux auditing solutions.  I am running a disconnected version of Splunk Enterprise and thus cannot make use of the content pack which replaced the application and add-on according to SplunkBase. 

Am I still able to use the archived applications and add-on? 

Realistically I am seeking a solution that would allow me to configure the universal forwarders I'm using to send the appropriate data so I can create queries via the linux_secure sourcetype.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Self-Healing Pipeline Is Now Generally Available: AI-Powered CIM Compliance

Maintaining data integrity across security and analytics pipelines is an ongoing challenge. Data ...

Meet Splunk Observability Studio: AI-Assisted OpenTelemetry Instrumentation Without ...

Instrumentation is usually the last step or even an afterthought when building out a project. The feature ...

Federated Search for Cisco Security and Analytics Logging (SAL) is now GA on Splunk ...

Federated Search for Cisco  Security Analytics and Logging (SAL) is now generally available as part of the ...