Hi,
I am using the free app "Check Point App for Splunk" on Splunk Enterprise 9.4. Splunk Enterprise will be upgraded to version 10. The URL Check Point App for Splunk | Splunkbase says it is supported on Splunk Enterprise version 9.4, but not on v10. I presume it may or may not work on Splunk Enterprise v10. Can someone using Splunk Enterprise v10 confirm whether the free app "Check Point App for Splunk" works as expected?
Thanks!
Adding to the already provided answers - this app was released by Checkpoint two years ago before certain business events happened. Therefore it is highly probable that due to political reasons the app will not be updated anymore by the vendor.
There is an alternative app - https://splunkbase.splunk.com/app/5478
Its status is "archived" (which could warrant pinging the support) but it should work OK and it's Splunk supported.
@theboss This app was built by Checkpoint itself, and the latest app version released almost two years ago where Splunk version 10 was not released at that time, hence not showing in compatibility section. I don't have a use case for Checkpoint specific, but general approach which I follow is to test it in our Dev splunk setup running with v10 and run the app inputs there to test for any errors related to Splunk version. You may also follow similar approach. Thanks.
>>
If this post addressed your question, you can:
Acknowledging helpful answers keeps the community strong and motivates contributors to continue sharing their expertise.
>>
Hi @theboss
I dont use the app myself but Ive had a look through the code for it and theres nothing that jumps out at that would cause too much concern ie deprecated python version dependency. However there is some Javascript in some of the dashboards although I personally havent experienced issues with this from 9->10.
If possible it would be worth installing a dev version of 10.x and installing the app to check you still have the same functionality without errors that you currently have. Things like the props/transforms etc shouldnt be an issue from 9->10.
In the meantime you could also raise an issue on their GitHub repo (https://github.com/CheckPointSW/Check_Point_App_for_Splunk) asking if they can confirm and/or update for v10.x
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing