Splunk Enterprise Security

Why is the Splunk_TA_paloalto missing from the install directory for Splunk Enterprise Security 4.1.0?

jwiedow
Communicator

The Splunk_TA_paloalto is missing from the SplunkEnterpriseSecuritySuite/install directory for Splunk Enterprise Security 4.1.0 and is not listed as a deprecated app in deprecated_apps.txt.

Is this intentional or an oversight when ES 4.1.0 was compiled?

Splunk_TA_paloalto is included in the SplunkEnterpriseSecuritySuite/install directory for ES versions 4.0.1 to 4.0.3.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Splunk_TA_paloalto was recently handed off to PAN for updates and maintenance going forward, with assistance from Splunk. The app ID and splunkbase entry hasn't changed, but because it's now supported & maintained by Palo Alto Networks it did not ship inside of Enterprise Security. You'll likely see updates release in concert with ES if not more often.

https://splunkbase.splunk.com/app/2757/

jwiedow
Communicator

Should it have been included in the SplunkEnterpriseSecuritySuite/install/deprecated_apps.txt file then since it was not released with ESS? I do not see it as a deprecated add-on/app as such where other add-ons/apps have been removed are in that file.

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

Hey JWeidow,
Excellent question and I'll check into the details for you. It might have been an oversight on not adding it to the deprecated_apps.txt file but let me figure that out. It's also a newer case where a strategic partner (Palo Alto Networks) has offered to take on development which is a soft of corner case. Hang tight for an update!

0 Karma

jwiedow
Communicator

To round out this conversation, the TA-rsa-4.0.3-3088.spl and TA-websense-4.0.3-3088.spl have also been removed from the SplunkEnterpriseSecuritySuite/install directory but are not listed in deprecated_apps.txt either.

All Three TAs have been removed from SplunkEnterpriseSecuritySuite/install/installable_apps.txt file if that helps.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...