Splunk Enterprise Security

Update SPLUNK_SA_CIM version

singhvishakha29
Engager

Hi All,

I would like to know about the process to update the CIM. I am currently getting the following errors:

Splunk_SA_CIM version 4.11.0 is lower than required 4.9.1

Could someone guide me through the process or any links?
TIA

0 Karma

koshyk
Super Champion

I guess the reason is due to internal splunk check but Zero padding missing.

The logic is done using SplunkEnterpriseSecuritySuite/bin/configuration_checks/confcheck_es_app_version.py
It compares the list of files from SplunkEnterpriseSecuritySuite/install/installable_apps.txt and a pre-requesite set of JSON file.
SplunkEnterpriseSecuritySuite-4.x.x file. You can either manipulate this file (after taking a copy)

or ensure that you have an Enterprise SEcurity you can upgrade to, which has the minimum check of Splunk_SA_CIM version of 4.10.x or something. Enterprise Security 4.7.6 works perfectly fine with CIM 4.10.0

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...