Is the GuardDuty Add-on officially supported on Splunk version 7.2? If not, are there plans to update it so it is supported?
It's supported on 7.2, however, there is more guidance here on best practices for working with GuardDuty data:
View solution in original post
Thank you, kchamplin!