All Applications

Want your Splunk with extra IT goodness?

Install Applications! The Splunk community has created a growing collection of downloads you can use to add all kinds of functionality to your Splunk server. Download (or make and share with others) reports, helpful configurations for processing particular types of data, or even tools built using the Splunk API. Want to learn how to create Applications?

Not a Splunk user? Download Splunk, set up your Splunk server, and then install your Applications(s) to extend your server.

More...

Screenshot

AfterGlow Graphing

This new search processor enables the generation of link graphs through Splunk. See the README for more information.

Author: raffy Type: Searches, Search Commands, Modules and Processors, Event Actions
Rating:
(3 votes)
Added: 9 months ago
Downloads: 561 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for PCI

The Splunk PCI application offers over 57 reports, more than 91 saved searches, a dashboard, and corresponding alerts you can use to satisfy PCI requirements such as secure remote access, file integrity monitoring, secure log collection, daily log review, audit trail retention, and PCI control reporting.

Author: Splunk Type: Searches, Reports, Event Types, Alerts
Rating:
(5 votes)
Added: 4 months ago
Downloads: 508 Last Updated: 3 days ago
License: 30 Day Trial Price: Email sales@splunk.com for pricing
Categories:
Screenshot

Splunk for Change Management

Splunk for Change Management provides predefined reports and dashboards to facilitate change auditing, change detection, change reporting, change validation and incident response based on change events, change tickets and configuration files. If you want to detect file changes with Splunk, you need to install Splunk on the systems that will have the changes. Splunk can be set up forwarder only. See http://www.splunk.com/doc/latest/admin/ForwardingandReceiving

Author: Splunk Type: Searches, Reports, Inputs, Fields, Event Types, Event Actions, Alerts
Rating:
(4 votes)
Added: 3 months ago
Downloads: 212 Last Updated: 19 days ago
License: 30 Day Trial Price: Email sales@splunk.com for pricing
Categories:

Arkeia

Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.

Author: maverick Type: Transactions, Searches, Reports, Fields, Event Types
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 30 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:

Cisco Pix Firewall Log Bundle

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Author: Splunk Type: Searches, Reports, Fields, Event Types
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 448 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:

feorlen_twitter_alert

Example of using a 3rd party REST endpoint with a Splunk custom processor. Post a message to Twitter for sourcetype::access_common events containing the string "wikipedia" and add status info to the event so it gets indexed. Includes C++ source and osx-i386 binary.

Author: andrea Type: Modules and Processors, Alerts, Custom Processing
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 18 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

Negative Searching Demo Bundle

This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.

Author: maverick Type: Searches, Reports, Inputs, Fields, Alerts
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 89 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:

IPFW - Field Definitions

This bundle contains field extractions for IPFW firewall log files.

Author: raffy Type: Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 51 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

PF - Field Definitions

This bundle contains field definitions for OpenBSD firewall events.

Author: raffy Type: Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 35 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

IPMI Fan Speeds

Gather and report on system fan speeds using ipmi

Author: markc Type: Inputs
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 73 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

Nessus Bundle

This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.

Author: maverick Type: Fields, Alerts, Reports, Searches
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 94 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:

nscreen

This bundle is for field extraction and reporting on netscreen firewalls

Author: jon Type: Fields, Searches
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 150 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:

Ironport field extractions

Provides file classification, date extraction, and extractions for ironport data.

Author: ssorkin Type: Custom Processing, Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 60 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

Brian's valgrind bundle

aggregates and extracts information from valgrind logs

Author: BSplunk Type: Fields, Searches
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 5 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:
None

Brian's crash report log bundle

Aggregates and extracts useful information from osx crash reporter logs.

Author: BSplunk Type: Fields, Reports
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 17 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:
None

steveyz_bundle

A few useful searches leveraging the monitoring bundle data, using the multikv operator

Author: steveyz Type: Searches, Reports
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 27 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

IMAP Addon

This Addon will continually download mail from an imap account where it is indexed by a splunk server. You can do cool things like see how often you get mail from someone, graph by size, time, etc.

Author: erik Type: Searches, Scripted Inputs, Inputs
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 147 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

OS Monitoring

This bundle will one or more system level monitoring utilities and index the output. By indexing the system information you can help correlate events in logs with OS level trajectory information.

Author: erik Type: Searches, Scripted Inputs, Inputs, Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 527 Last Updated: 19 days ago
License: Creative Commons Price: Free
Categories:
Screenshot

Web Page Monitor

This bundle will check a set of webpages every interval and index the result, time, size and optionally content and or crc of page(s). Its cool to do searches to see when your pages change, take long to load, or many other cool things.

Author: erik Type: Searches, Scripted Inputs, Inputs, Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 209 Last Updated: 7 months ago
License: Creative Commons Price: Free
Categories:

javac++ bundle

adds reasonably good support for C++ and Java source code by breaking functions, classes, and structs into different events.

Author: carasso Type: Inputs
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 23 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

adds support for anonymizing log files at index time

anonymizes ip address as 127.0.0.1 (localhost); email addresses as user@domain.com ; social-security-numbers as 555-00-0000; password/passwd looking values as 'password' ; username/userid/login/user looking values as 'bob'.

Author: carasso Type: Custom Processing, Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 14 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

Linux Failed Login

A series of saved searches to detect common login failures on Linux hosts.

Author: m@ Type: Searches
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 93 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:

Dee's wtmp input bundle

Help Splunk to index the output of last (from /var/log/wtmp), even though it's in a binary format.

Author: deeann Type: Scripted Inputs, Inputs
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 60 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

SMART Disk Reporting

This bundle outputs this text : === START OF INFORMATION SECTION === Model Family= Seagate Momentus 7200.1 series Device Model= ST910021AS Serial Number= 3MH0498W Firmware Version= 3.07 User Capacity= 100,030,242,816 bytes Device is= In smartctl database [for details use: -P show] ATA Version is= 7 ATA Standard is= Exact ATA specification draft version not indicated Local Time is= Mon Aug 20 00:38:18 2007 PDT SMART support is= Available - device has SMART capability. SMART support is= Enabled === START OF READ SMART DATA SECTION === SMART overall-health self-assessment test result= PASSED Which is then indexed by Splunk.

Author: markc Type: Inputs
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 87 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories: