Splunk Enterprise

Can I Install an add-on in Splunk Light offline?

ProtechtSplunk
Engager

Because of security reasons, my Splunk server can't be given Internet access. Is there a way to install an Add-on manually on the Splunk console? I have found a solution that suggested to download the Add-on, transfer it to the Splunk server, and select "Choose from File", but I can't find this option in the Add-on.

krushio
Engager

After downloading an add on from splunk website, it provides you an option to see the steps on how to install the add on.
For example a dataset addon

Installation:

Download the Splunk Datasets Add-on. The file downloads with a .tar.gz extension. Do not attempt to run this file.
Save the archive in an accessible location.
Log into Splunk Enterprise on the host on which you want to install the Splunk Datasets Add-on.
In the Home screen, select Apps > Manage Apps.
Click Install app from file.
Click Choose file and locate the installation package you just uploaded.
Click Upload. Your Splunk instance installs the Splunk Datasets Add-on.

alt text

Something close to that: I do not know if it applies to all add on. But it is important to follow their instructions since splunk provides instructions to most of their installations

0 Karma

ChrisG
Splunk Employee
Splunk Employee

There are only three add-ons for Splunk Light at this time: Cisco ASA, Windows, and Unix/Linux.

https://splunkbase.splunk.com/apps/#/page/1/product/lite/order/latest

If you don't see them appearing in the add-ons page within Splunk Light, then you can't use them with that product.

Unix/Linux and Cisco ASA you should be able to enable without installing.

The Windows add-on does require installation by default, in which case you can download it separately and follow the instructions in the Splunk Add-on for Windows documentation.

fdi01
Motivator

another method
- unzipped simply your Add-on that you download
- Then you copy it and you're going to stick it in your SPLUNK_HOME directory / etc / apps /
- then you Restart

Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...