remg427 / TA-thehive

Splunk TA for alert action to TheHive-project
GNU Lesser General Public License v3.0
11 stars 3 forks source link

Splunk Cloud Support? #23

Closed MineshK closed 4 years ago

MineshK commented 4 years ago

Hi,

Would be great if this was supported on Splunk Cloud, so we can try it out. I think it needs to be certified by them before they will install it.

Any chance it will be certified by Splunk for Cloud?

Thanks

remg427 commented 4 years ago

Hi, Other have managed to get it on cloud but later Splunk changed policy and inputs are no longer allowed in search heads. I am working on a cloud edition that should be vetted.

-- Sent with K-9 Mail.

remg427 commented 4 years ago

Hello have a look at TA-thehive-ce.tar.gz this one should be OK. Don't ask for vetting process yet as I am waiting for feedback first and I still need to update splunklib with latest version 1.6.11

MineshK commented 4 years ago

Hi Rémi,

Thanks for the quick reply - I just tried it, and no joy:

The failure is for the following: Do not supply a local.meta file- put all settings in default.meta. File: metadata/local.meta

There are a number of warnings too - these are not blockers, but ma be worth getting ahead of for a later version:

check_custom_confs

check_for_valid_package_id The app.conf [package] stanza's has 'id' property: TA-thehive-ce, while '-' is not recommended. See https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Appconf for more details. File: default/app.conf Line Number: 19

check_splunklib_dependency_under_bin_folder

Cheers

remg427 commented 4 years ago

Hello, for the CE edition go to repository TA-thehive-ce. I have made some changes and version 1.0.1 should OK for Cloud vetting some warnings above have been solved (not all yest)