Splunkbase Archive

The Archive supports a collection of apps for Splunk prior to version 4.0. Browse the menu at left to find apps or add-ons by the category of solution they provide or the Splunk function they're built for. To learn more about installing apps in Splunk 3.x, check the Adminstration Manual for your version.

AfterGlow for Splunk 3.x

This search processor enables the generation of link graphs through Splunk. Make sure you follow the instructions in the README (once installed, located in etc/apps/afterglow) to configure the application!

Splunk Version: 3.x | Author: raffy | Categories: More »

Splunk Assist Application

The Splunk assist application is to be used for troubleshooting, monitoring, and enhancing the performance of Splunk. The application contains a group of files that contains searches and configuration options that will assist in your use of Splunk.

Splunk Version: 3.x | Author: Splunk | Category: More »

Splunk for UNIX (Splunk 3 Compatible)

The Splunk for UNIX application is a compilation of a dashboard, saved searches, eventtypes, and field extractions that work for various flavors of UNIX. In addition, the application also ships with a set of scripted inputs that can be used to monitor UNIX machines. Inputs like top, ps, vmstat, iptables, and netstat, are supported.

Splunk for PCI for Splunk 3.x

The Splunk PCI application offers over 57 reports, more than 91 saved searches, a dashboard, and corresponding alerts you can use to satisfy PCI requirements such as secure remote access, file integrity monitoring, secure log collection, daily log review, audit trail retention, and PCI control reporting.

Splunk Version: 3.x | Author: Splunk | Category: More »

Reverse Name Resolution Search Script (DNS)

This search script (nslookup.py) will perform reverse name lookup on every IP from an event at search time.

Splunk Enterprise Manager

A Splunk application that provides visibility into the connectivity of Splunk forwarders to one or more indexers, the availability of Splunk forwarders and indexers, the data volumes passed by forwarders and the data volumes consumed by indexers. Displayed within a dashboard view.

Splunk Version: 3.x | Author: 76trombones | Category: More »

Splunk for OSSEC

Field extraction for OSSEC HIDS(http://www.ossec.net)

Splunk for VMware ESX Management

Splunk indexes all IT data across every tier - the physical servers, hypervisor, VMs, and deployed applications, capturing and persisting 100% of your data in real-time. It includes inputs, indexing, searches, reports and dashboards.

Splunk for Change Management

Splunk for Change Management provides predefined reports and dashboards to facilitate change auditing, change detection, change reporting, change validation and incident response based on change events, change tickets and configuration files.

Splunk Version: 3.x | Author: Splunk | Category: More »

splunk2nagios

This add-on helps you set up Splunk to Nagios integration

Splunk Version: 3.x | Author: Splunk | Category: More »

Script for database inputs

This script is designed to be used as a scripted input for data contained in database tables. Plese refer to the Splunk Admin guide for more information on configuring scripted inputs. The script has been successfully used in a number of deployments, and should work with Oracle, MySQL, and sybase databases as-is. Other database types can be added by installing the appropriate perl DBD module, and editing the script to configure for the new dbtype. In this version, all of the SQL code has been abstracted from the script, and all parameters including the query are passed as commandline arguments to the script.

Splunk for Windows for Splunk 3.x

Splunk for Windows application is a compilation of saved searches, eventtypes, inputs, and field extractions for Windows. The extractions are compatible with the Splunk Common Information Model. The application also contains an integration for Microsoft’s System Center Operations Manager.

Splunk Version: 3.x | Author: Splunk | Category: More »

Google Earth / Google Maps

This bundle adds new field actions for IP addresses to locate the geographic origin of a connection.

Splunk Version: 3.x | Author: raffy | Category: More »

Splunk for Network Security

The Splunk Network Security application offers a set of reports, saved searches, and dashboards, as well as corresponding alerts that you can use to monitor your firewalls, intrusion detection and prevention systems, as well as operating systems.

Splunk Version: 3.x | Author: Splunk | Category: More »

Arkeia

Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.

Splunk for CISCO PIX

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Splunk Version: 3.x | Author: Splunk | Category: More »

feorlen_twitter_alert

Example of using a 3rd party REST endpoint with a Splunk custom processor. Post a message to Twitter for sourcetype::access_common events containing the string "wikipedia" and add status info to the event so it gets indexed. Includes C++ source and osx-i386 binary.

Splunk Version: 3.x | Author: andrea | Category: More »

Negative Searching Demo Bundle

This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.

Splunk Version: 3.x | Author: maverick | Category: More »

IPFW Firewall

This application contains field extractions and eventtypes for IPFW firewall log files.

Splunk Version: 3.x | Author: raffy | Category: More »

OpenBSD Packet Filter

This bundle contains field extractions and eventtypes for OpenBSD firewall events.

Splunk Version: 3.x | Author: raffy | Category: More »

IPMI Fan Speeds

Gather and report on system fan speeds using ipmi

Splunk Version: 3.x | Author: markc | Categories: More »

Nessus Bundle

This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.

Splunk for Netscreen

This app provides field extraction and event types for Netscreen firewalls. The extractions are compatible with the Splunk common information model.

Splunk Version: 3.x | Author: Splunk | Category: More »

Ironport field extractions

Provides file classification, date extraction, and extractions for ironport data.

Splunk Version: 3.x | Author: ssorkin | Category: More »