Hardware and software requirements for the Splunk Add-on for OSSEC
Splunk admin requirements
To install and configure the Splunk Add-on for OSSEC, you must be member of the admin or sc_admin role.
OSSEC setup requirements
You must have access to the OSSEC installation directory so that you can configure your OSSEC server to send alert data to the Splunk platform over syslog.
Splunk platform requirements
Because this add-on runs on the Splunk platform, all of the system requirements apply for the Splunk software that you use to run this add-on.
- For Splunk Enterprise system requirements: see "System Requirements" in the Installation Manual in the Splunk Enterprise documentation.
- If you are managing on-premises forwarders to get data in to Splunk Cloud, see "System Requirements" in the Installation Manual in the Splunk Enterprise documentation, which includes information about forwarders.
About the Splunk Add-on for OSSEC | Installation and configuration overview for the Splunk Add-on for OSSEC |
This documentation applies to the following versions of Splunk® Supported Add-ons: released
Feedback submitted, thanks!