Splunk Enterprise Security

Question RE: Enterprise Security Compatibility with Add-On for Microsoft Windows

richardphung
Communicator

We are planning an upgrade.
Our current environment:

  • Splunk Enterprise Core - 7.1.4
  • Enterprise Security - 5.1.1
  • Splunk Add-On for Microsoft Windows - 5.0.1
  • Splunk Add-On for Microsoft Active Directory - 1.0.0

Our target for this maintenance window is proposing to bring this to:

  • Splunk Enterprise Core - 7.3.3
  • Enterprise Security - 6.0.0

The question is do we need to also plan to upgrade the Splunk Add-On for Microsoft Windows from 5.0.1 to 6.x/7.x?
As well as deprecate Splunk Add-On for Microsoft Active Directory at the same time? or will these continue to work, and we can plan for a future deployment of the latest supported MS-Add-Ons?

Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...