I have a customer that is upgrading Splunk Core from 6.3.3 to 7.1 and Splunk Enterprise Security (ES)/CIM from 4.7.2 to 5.2. They are upgrading apps first and some do not explicitly say CIM compatible with ES 5.2. Could this be an issue or are apps generally CIM backwards compatible? For example, the Cisco Security Suite is compatible with Splunk 7.0 and CIM 4.4. Would this be an issue?
... View more
I ask because PAN has two locations for TRAPS, on-prem (ESM) and in the cloud (TMS). The TMS uses the logging service and the log format is different. We want to move a customer to the cloud with TMS, which will use the Logging Service. The customer use-case is seeing reports/dashboards that confirm malware is being blocked/prevented.
... View more