We are running Splunk7.3.0.
We have installed:
1 - ModSecurity Add-On for Splunk on both the indexer and search head following the instructions here:
https://splunkbase.splunk.com/app/3391/#/details
2 - The TA-user-agents on both the indexer and search head following the instructions here:
https://splunkbase.splunk.com/app/1843/#/details
3 - The ModSecurity App for Splunk on the search head following the instructions here:
https://splunkbase.splunk.com/app/3392/#/details
Issue:
Searching via the GUI and search app is successful, however there is nothing populated in the ModSecurity app for Splunk.
The compatibility list for 2 of these components list versions prior to 7.3
Any suggestions please?
... View more