[Current users of the Splunk Expanse TA] If you are upgrading to v3.0.0 from a previous version of the Expanse Splunk TA, you need to reach out to your Expanse Engagement Manager for upgrade instructions.
What's new in this release:
Ability to ingest Expander Issues Update data
Deprecation of Exposures and Events data ingestion
Python 2 and Python 3 dual compatibility
Daily asset refreshes (weekly refreshes in previous versions)
Supported larger Behavior customers via checkpointing changes.
- Added support for domains and certificates
- Fixed a bug in Behavior
* Adds support for ingesting Behavior data
* Adds support for ingesting Exposure data for lookups
* Includes minor bug-fixes
Added automated mapping of Asset data to Events
Added additional Input settings for better operationalization in distributed environments.
Business unit names and IDs now appear when viewing the asset data fields.
Note: This fix will apply immediately upon installation of the latest version of the Expanse Expander Technical Add-on
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.