Splunk Enterprise Security

Will the correlation that ES works off of with the Add-on cause issues in finding the data if I have version 5.0 in the environment and version 4.8.4 in ES?

Crashfry
Path Finder

I'm running into an issue with Enterprise Security (ES) - correlation with event types with Add-ons.

The example I have is with the Windows Add-on. I have version 5.0 in the environment but with ES I have version 4.8.4 - will the correlation that ES works off of with the Add-on cause issues in finding the data?

0 Karma
1 Solution

Crashfry
Path Finder

Answered my own question - it's important with the changes of tags and event types - specifically with this situation and the windows add-on.

View solution in original post

0 Karma

Crashfry
Path Finder

Answered my own question - it's important with the changes of tags and event types - specifically with this situation and the windows add-on.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...