The Splunk_TA_paloalto is missing from the SplunkEnterpriseSecuritySuite/install directory for Splunk Enterprise Security 4.1.0 and is not listed as a deprecated app in deprecated_apps.txt.
Is this intentional or an oversight when ES 4.1.0 was compiled?
Splunk_TA_paloalto is included in the SplunkEnterpriseSecuritySuite/install directory for ES versions 4.0.1 to 4.0.3.
Splunk_TA_paloalto was recently handed off to PAN for updates and maintenance going forward, with assistance from Splunk. The app ID and splunkbase entry hasn't changed, but because it's now supported & maintained by Palo Alto Networks it did not ship inside of Enterprise Security. You'll likely see updates release in concert with ES if not more often.
Should it have been included in the SplunkEnterpriseSecuritySuite/install/deprecated_apps.txt file then since it was not released with ESS? I do not see it as a deprecated add-on/app as such where other add-ons/apps have been removed are in that file.
Hey JWeidow,
Excellent question and I'll check into the details for you. It might have been an oversight on not adding it to the deprecated_apps.txt file but let me figure that out. It's also a newer case where a strategic partner (Palo Alto Networks) has offered to take on development which is a soft of corner case. Hang tight for an update!
To round out this conversation, the TA-rsa-4.0.3-3088.spl and TA-websense-4.0.3-3088.spl have also been removed from the SplunkEnterpriseSecuritySuite/install directory but are not listed in deprecated_apps.txt either.
All Three TAs have been removed from SplunkEnterpriseSecuritySuite/install/installable_apps.txt file if that helps.