Networking Applications

Not a Splunk user? Download Splunk, set up your Splunk server, and then install your Applications(s) to extend your server.

More...

Screenshot

Splunk for CISCO PIX

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Author: Splunk Type: Searches, Reports, Fields, Event Types
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 1,390 Last Updated: 3 days ago
License: Creative Commons Price: Free
Categories:

IPFW Firewall

This application contains field extractions and eventtypes for IPFW firewall log files.

Author: raffy Type: Fields
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 171 Last Updated: 20 days ago
License: Creative Commons Price: Free
Categories:
Screenshot

OpenBSD Packet Filter

This bundle contains field extractions and eventtypes for OpenBSD firewall events.

Author: raffy Type: Fields
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 141 Last Updated: 20 days ago
License: Creative Commons Price: Free
Categories:

nscreen

This bundle is for field extraction and reporting on netscreen firewalls

Author: jon Type: Fields, Searches
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 487 Last Updated: 6 months ago
License: Creative Commons Price: Free
Categories:

Google Earth / Google Maps

This bundle adds new field actions for IP addresses to locate the geographic origin of a connection.

Author: raffy Type: Event Actions
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 425 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

Enable SSL in Splunk

A quick and simple add-on that enables SSL for your pre-3.2 Splunk server and Web interface.

Author: deeann Type: Custom Processing
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 101 Last Updated: 11 months ago
License: Creative Commons Price: Free
Categories:

getdevicetype

This search command will parse a csv file exported by network or systems device management software and match the hostnames/ip addresses in the file to host field values in you Splunk search, returning the new field devicetype for every match. The csv location is specified at the top of the script, and if you wish you can also alter the field matching to something other than "host" by changing the field variable in the script. The csv must be in the format "device_name,device_type". Thus, you can type: login | getdevicetype | where devicetype="cisco6500" to get only logins on cisco6500 devices or login | getdevicetype to get devicetype to display as a field below each event and be filterable and clickable like host and hosttag. or login | getdevicetype | top devicetype to get a report of number of events by devicetype.

Author: araitz Type: Search Commands
Rating: Awaiting 3 votes Added: 12 months ago
Downloads: 62 Last Updated: 12 months ago
License: Creative Commons Price: Free
Categories:

CheckPoint OPSEC LEA Application

This application contains an OPSEC LEA application to drop into Splunk 3.0 or later, offering a client, event types, and field extractions. It functions on Linux and on Solaris with gmake and gcc installed. The application conforms with the Splunk application standard, meaning that it uses common field names for its data.

Author: Splunk Type: Scripted Inputs, Fields, Event Types, Clients
Rating: Awaiting 3 votes Added: 11 months ago
Downloads: 231 Last Updated: 4 months ago
License: Creative Commons Price: Free
Categories:

Checkpoint Event Field Extraction

Search-time parsing of following fields: loc, time, action, orig, i/f_dir, i/f_name, has_accounting, uuid, product, src, dst, proto, rule

Author: goldburtd Type: Fields
Rating: Awaiting 3 votes Added: 11 months ago
Downloads: 89 Last Updated: 11 months ago
License: Creative Commons Price: Free
Categories:

Watchguard Firebox

Field Extractions for Watchguard Firebox

Author: araitz Type: Fields
Rating: Awaiting 3 votes Added: 11 months ago
Downloads: 102 Last Updated: 11 months ago
License: Creative Commons Price: Free
Categories:

Sonicwall Firewall

This bundle performs field extractions for sonicwall TZ 170 without the UTM/IDS modules

Author: araitz Type: Fields
Rating: Awaiting 3 votes Added: 9 months ago
Downloads: 101 Last Updated: 9 months ago
License: Creative Commons Price: Free
Categories:

iptables fields, inputs, and event types

This add-on applies to iptables firewall logs, normalizing their field names so they work well with other Splunk applications.

Author: Splunk Type: Inputs, Fields, Event Types
Rating: Awaiting 3 votes Added: 8 months ago
Downloads: 266 Last Updated: 8 months ago
License: Creative Commons Price: Free
Categories:

Splunk Alert

Command line utility to more easily search the splunk database, log specific errors and execute commands on a match. Comes with several predefined searches for cisco networking, and is easily extended. -s search Predefined search to run, use 'list' for options -cs string Custom search string passed in with quotes -l file Log results to file, appends by default -e email_addr Email addresses comma separated -x command Execute a command on a match -t time_restrict Suppress email alerts by time of day, use 'list' for options -d days Search over this many days in the past (default: 1) -m minutes Search over this many minutes in the past -c maxnum Max number of results (default: 100) -r Reverse results, (newest to oldest) -w Raw results, do not strip off timestamps -q Quiet Output, suppress errors -v Verbose output

Author: yantisj Type: Searches, Event Actions, Custom Processing, Alerts
Rating: Awaiting 3 votes Added: 5 months ago
Downloads: 212 Last Updated: 5 months ago
License: Creative Commons Price: Free
Categories:

Splunk for Network

This is a simple application to monitor change on network device configurations. It runs a scripted input to request the network device upload it's configuration file to a tftp server. The input reads /tftpboot for any files that get uploaded and indexes them through the fschange source.

Author: Splunk Type: Inputs
Rating: Awaiting 3 votes Added: 4 months ago
Downloads: 364 Last Updated: 2 days ago
License: Creative Commons Price: Free
Categories:

Reverse Name Resolution Search Script (DNS)

This search script (nslookup.py) will perform reverse name lookup on every IP from an event at search time.

Author: rataide Type: Search Commands
Rating: Awaiting 3 votes Added: 3 months ago
Downloads: 214 Last Updated: 5 days ago
License: Creative Commons Price: Free
Categories: