Installing additional Splunk add-ons and apps
Now that we have our components installed, let’s revisit the BOTS Dataset v1
app. In order to use the dataset, we will need to install some additional Splunk add-ons and apps. Download the following add-ons and apps from Splunkbase:
- Fortinet FortiGate Add-On for Splunk (https://splunkbase.splunk.com/app/2846/)
- TA for Suricata (https://splunkbase.splunk.com/app/4242/)
- Splunk Add-on for Stream Wire Data (https://splunkbase.splunk.com/app/5234/)
- Nessus (https://splunkbase.splunk.com/app/5918/)
It’s important to note that some apps may contain configurations that require them to be installed on different Splunk components. Splunk Add-on for Windows, which we deployed to the forwarders, is one of those apps. The add-on is needed on the Splunk forwarders because of the input configurations—that is, a set of configurations that tell Splunk how to find the data sources that we will be ingesting. However...