Splunk Enterprise Security

Splunk Security Essentials

bennett_riegel
New Member

I've downloaded the splunk security essential files all into my laptop, but I can't figure out how to upload into into splunk enterprise as an app. What is my next step and where do I go to do this?

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

you should follow these instructions https://docs.splunk.com/Documentation/SSE/3.7.1/Install/InstallSSE

If you have different version then select correct documentation based on your version.

r. Ismo

0 Karma

inventsekar
SplunkTrust
SplunkTrust

>>> I've downloaded the splunk security essential files all into my laptop

May we know if you downloaded the single tar file (For example, ..splunk-security-essentials_371.tgz)


>>> but I can't figure out how to upload into into splunk enterprise as an app. What is my next step and where do I go to do this?

after downloading that tar file (for example..."splunk-security-essentials_371.tgz"), on your splunk, pls go to 

(left side Apps dropdown) Apps -- - > Manage Apps --- > Install app from file.

then select the tar file and load it, it will install smoothly.. then splunk restart will be required. 

0 Karma

bennett_riegel
New Member

I'm in the install app from file section, and I've downloaded the security essentials, but I don't see a file to put in there. What is the exact name of it because I feel like I've tried all of them? 

0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @bennett_riegel 
1. did you download the app as a tar file from the Splunkbase
(the file name looks like "splunk-security-essentials_371.tgz")

2. on your Splunk, pls go to 

(left side Apps dropdown) Apps -- - > Manage Apps --- > Install app from file.

3. then select the tar file("splunk-security-essentials_371.tgz") and load it, it will install smoothly..
4. then Splunk restart will be required. 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...