Requirements:
- This Add-on is intended to be installed following the installation guide.
- Install Add-on Nozomi Networks Sensor Add-on (https://splunkbase.splunk.com/app/5316) version 1.3.2 or higher
Installation:
This Add-on is intended to be installed on Search Head as a companion for the following add-on:
- Install Add-on Nozomi Networks Sensor Add-on (https://splunkbase.splunk.com/app/5316) version 1.3.2 or higher
Known issues:
Check listed issues under the Troubleshooting section
Addressed Issues:
- Fix issues detected on sourcetype "nozomi:alert" with fields "type" and "severity" not outputting expected values.
Requirements:
- This Add-on is intended to be installed following the installation guide.
- Install Add-on Nozomi Networks Sensor Add-on (https://splunkbase.splunk.com/app/5316) version 1.3.2 or higher
Installation:
This Add-on is intended to be installed as follows:
- Splunk Cloud Victoria STACKs: Installed on Search Head
- Splunk Cloud Classic STACKs: Installed on Search Heads
- Splunk Enterprise: Installed on Search Heads
This Add-on is intended to be installed as a companion for the following add-on:
- Install Add-on Nozomi Networks Sensor Add-on (https://splunkbase.splunk.com/app/5316) version 1.3.2 or higher
Known issues:
- Modify manually "Eventtype": disable eventtype "nozomi_all_alerts" and tags for "nozomi_all_alerts"
- Modify manually "Calculated Field" (nozomi:alert): copy "Calculated Fields" search "signature", "protocol", and "severity" from CCX Add-on for Nozomi Networks Extension into the default configuration
- Modify manually "Calculated Field" (nozomi:node): copy "Calculated Fields" search "vendor_product" from CCX Add-on for Nozomi Networks Extension into the default configuration
- Modify manually "Calculated Field" (nozomi:nn_asset): copy "Calculated Fields" search "vendor_product", and "os" from CCX Add-on for Nozomi Networks Extension into the default configuration
- Modify manually "Eventtype": remove tags "performance", and "os" from eventtype "nozomi_all_nn_assets"
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.