Splunk Enterprise Security

Why is the Splunk_TA_paloalto missing from the install directory for Splunk Enterprise Security 4.1.0?

jwiedow
Communicator

The Splunk_TA_paloalto is missing from the SplunkEnterpriseSecuritySuite/install directory for Splunk Enterprise Security 4.1.0 and is not listed as a deprecated app in deprecated_apps.txt.

Is this intentional or an oversight when ES 4.1.0 was compiled?

Splunk_TA_paloalto is included in the SplunkEnterpriseSecuritySuite/install directory for ES versions 4.0.1 to 4.0.3.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Splunk_TA_paloalto was recently handed off to PAN for updates and maintenance going forward, with assistance from Splunk. The app ID and splunkbase entry hasn't changed, but because it's now supported & maintained by Palo Alto Networks it did not ship inside of Enterprise Security. You'll likely see updates release in concert with ES if not more often.

https://splunkbase.splunk.com/app/2757/

jwiedow
Communicator

Should it have been included in the SplunkEnterpriseSecuritySuite/install/deprecated_apps.txt file then since it was not released with ESS? I do not see it as a deprecated add-on/app as such where other add-ons/apps have been removed are in that file.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Hey JWeidow,
Excellent question and I'll check into the details for you. It might have been an oversight on not adding it to the deprecated_apps.txt file but let me figure that out. It's also a newer case where a strategic partner (Palo Alto Networks) has offered to take on development which is a soft of corner case. Hang tight for an update!

0 Karma

jwiedow
Communicator

To round out this conversation, the TA-rsa-4.0.3-3088.spl and TA-websense-4.0.3-3088.spl have also been removed from the SplunkEnterpriseSecuritySuite/install directory but are not listed in deprecated_apps.txt either.

All Three TAs have been removed from SplunkEnterpriseSecuritySuite/install/installable_apps.txt file if that helps.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...