Splunk Enterprise Security

Why is the Splunk_TA_paloalto missing from the install directory for Splunk Enterprise Security 4.1.0?

jwiedow
Communicator

The Splunk_TA_paloalto is missing from the SplunkEnterpriseSecuritySuite/install directory for Splunk Enterprise Security 4.1.0 and is not listed as a deprecated app in deprecated_apps.txt.

Is this intentional or an oversight when ES 4.1.0 was compiled?

Splunk_TA_paloalto is included in the SplunkEnterpriseSecuritySuite/install directory for ES versions 4.0.1 to 4.0.3.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Splunk_TA_paloalto was recently handed off to PAN for updates and maintenance going forward, with assistance from Splunk. The app ID and splunkbase entry hasn't changed, but because it's now supported & maintained by Palo Alto Networks it did not ship inside of Enterprise Security. You'll likely see updates release in concert with ES if not more often.

https://splunkbase.splunk.com/app/2757/

jwiedow
Communicator

Should it have been included in the SplunkEnterpriseSecuritySuite/install/deprecated_apps.txt file then since it was not released with ESS? I do not see it as a deprecated add-on/app as such where other add-ons/apps have been removed are in that file.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Hey JWeidow,
Excellent question and I'll check into the details for you. It might have been an oversight on not adding it to the deprecated_apps.txt file but let me figure that out. It's also a newer case where a strategic partner (Palo Alto Networks) has offered to take on development which is a soft of corner case. Hang tight for an update!

0 Karma

jwiedow
Communicator

To round out this conversation, the TA-rsa-4.0.3-3088.spl and TA-websense-4.0.3-3088.spl have also been removed from the SplunkEnterpriseSecuritySuite/install directory but are not listed in deprecated_apps.txt either.

All Three TAs have been removed from SplunkEnterpriseSecuritySuite/install/installable_apps.txt file if that helps.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Introducing Splunk 10.0: Smarter, Faster, and More Powerful Than Ever

Now On Demand Whether you're managing complex deployments or looking to future-proof your data ...

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...