Installation

Graph Security Addon

tejasode
Observer

https://splunkbase.splunk.com/app/4564

Hi All, want to know the status on usage of particular app ,as we are seeing app being deprecated ,is there any alternate app/addon in leveraging the same functionality.

Current App stopped working 

Regards

Teja 

Labels (3)
0 Karma

tej57
Contributor

Hey @tejasode ,

Not sure why you mention the app to be archived. I see that the app is available for use and download as well. Additionally, the similar inputs can also be found in Microsoft Azure Add-on for Splunk (https://splunkbase.splunk.com/app/3757). There are a lot of add-ons available on Splunkbase to fetch data from Azure. Can you elaborate more on what particular functionality are you looking for?

Thanks,
Tejas.

0 Karma

tejasode
Observer

Hi , Sorry if any confusion on my comments, i am not asking that app should be archived.

We have this app installed on our SH since long now and all of sudden app stopped working, post we raised a case with SPlunk ,  they mentioned app got deprecated.

Now i am checking if there is any alternate option to onboard the CAS(cloud app security) logs.

As per your comments,If  App is still active , then why the console is  not opening?


0 Karma

tej57
Contributor

Hey @tejasode ,

To check why the app console is currently not opening, it should be better to check splunkd.log and web_service.log. Apart from that for alternative solution, as I mentioned #3757 (Splunk Add-on for Microsoft Azure) has inputs to collect data from Azure Security Center. 

Additionally, if you're able to stream the CAS logs to eventhub, you can also go for configuring #3110 (Splunk Add-on for Microsoft Cloudservices) inputs. It is also a supported add-on and is CIM compliant as well. 

Thanks,
Tejas.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...