Getting Data In

Looking for solutions for Linux/Unix Auditing?

kymenope
Explorer

Fairly new Splunk user here looking for Linux auditing solutions.  I am running a disconnected version of Splunk Enterprise and thus cannot make use of the content pack which replaced the application and add-on according to SplunkBase. 

Am I still able to use the archived applications and add-on? 

Realistically I am seeking a solution that would allow me to configure the universal forwarders I'm using to send the appropriate data so I can create queries via the linux_secure sourcetype.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...