Is the GuardDuty Add-on officially supported on Splunk version 7.2? If not, are there plans to update it so it is supported?
Thank you.
It's supported on 7.2, however, there is more guidance here on best practices for working with GuardDuty data:
https://www.splunk.com/blog/2018/02/22/serving-it-up-with-aws-and-splunk-aws-serverless-application-...
Thank you, kchamplin!
It's supported on 7.2, however, there is more guidance here on best practices for working with GuardDuty data:
https://www.splunk.com/blog/2018/02/22/serving-it-up-with-aws-and-splunk-aws-serverless-application-...