Getting Data In

Looking for solutions for Linux/Unix Auditing?

kymenope
Explorer

Fairly new Splunk user here looking for Linux auditing solutions.  I am running a disconnected version of Splunk Enterprise and thus cannot make use of the content pack which replaced the application and add-on according to SplunkBase. 

Am I still able to use the archived applications and add-on? 

Realistically I am seeking a solution that would allow me to configure the universal forwarders I'm using to send the appropriate data so I can create queries via the linux_secure sourcetype.

Labels (1)
0 Karma
1 Solution

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

View solution in original post

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

I'm not sure if I understood right your question.

There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.

That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...