Splunk Enterprise Security

Splunk Security Essentials

bennett_riegel
New Member

I've downloaded the splunk security essential files all into my laptop, but I can't figure out how to upload into into splunk enterprise as an app. What is my next step and where do I go to do this?

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you should follow these instructions https://docs.splunk.com/Documentation/SSE/3.7.1/Install/InstallSSE

If you have different version then select correct documentation based on your version.

r. Ismo

0 Karma

inventsekar
SplunkTrust
SplunkTrust

>>> I've downloaded the splunk security essential files all into my laptop

May we know if you downloaded the single tar file (For example, ..splunk-security-essentials_371.tgz)


>>> but I can't figure out how to upload into into splunk enterprise as an app. What is my next step and where do I go to do this?

after downloading that tar file (for example..."splunk-security-essentials_371.tgz"), on your splunk, pls go to 

(left side Apps dropdown) Apps -- - > Manage Apps --- > Install app from file.

then select the tar file and load it, it will install smoothly.. then splunk restart will be required. 

0 Karma

bennett_riegel
New Member

I'm in the install app from file section, and I've downloaded the security essentials, but I don't see a file to put in there. What is the exact name of it because I feel like I've tried all of them? 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @bennett_riegel 
1. did you download the app as a tar file from the Splunkbase
(the file name looks like "splunk-security-essentials_371.tgz")

2. on your Splunk, pls go to 

(left side Apps dropdown) Apps -- - > Manage Apps --- > Install app from file.

3. then select the tar file("splunk-security-essentials_371.tgz") and load it, it will install smoothly..
4. then Splunk restart will be required. 

0 Karma
Get Updates on the Splunk Community!

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...

Cloud Platform & Enterprise: Classic Dashboard Export Feature Deprecation

As of Splunk Cloud Platform 9.3.2408 and Splunk Enterprise 9.4, classic dashboard export features are now ...

Explore the Latest Educational Offerings from Splunk (November Releases)

At Splunk Education, we are committed to providing a robust learning experience for all users, regardless of ...