Fields Apps

Splunkbase is home to the apps and add-ons that run on top of Splunk. Browse the latest apps below, or share your own with the rest of the Splunk community. To learn more about Splunk and download a free Enterprise Trial of our software, visit Splunk.com.

Want to custom-define fields in your events?

Field apps let you download field definitions to install in your Splunk server, or share fields you made yourself! Even better, an app can have more than one type of content, so you can add fields to any app.

Geo Location Lookup Script

Splunk for Use with MAXMIND is an application that provides geo_ip information on any public IP in your Splunk DB in a scalable fashion. The GeoIPCityLite DB is apart of the app so no internet connection is required and lookups are performed locally on your search head. The use is simple, pipe any search to ' lookup geoip clientip as <some_ip_field> ' If you do not have an IP field in your data you can use the rex command to extract one and perform a lookup Example Searches: eventtype=firewall_event | lookup geoip clientip as src_ip sourcetype=syslog | rex field=_raw "(?<ip>\d+\.\d+\.\d+\.\d+)" | lookup geoip clientip as ip This product includes GeoLite data created by: MaxMind available from: http://www.maxmind.com/

Type: Add-On | Splunk Version: 4.x | Author: will More »
Screenshot

Splunk for UNIX (Splunk 3 Compatible)

The Splunk for UNIX application is a compilation of a dashboard, saved searches, eventtypes, and field extractions that work for various flavors of UNIX. In addition, the application also ships with a set of scripted inputs that can be used to monitor UNIX machines. Inputs like top, ps, vmstat, iptables, and netstat, are supported.

Type: Monitoring | Splunk Version: 3.x | Author: Splunk More »

Splunk reverse DNS lookup for fields

Replaces IP addresses in specified fields with the results of a DNS lookup of the field contents. Pipe results to the "nsresolve" command, specifying the fields to replace, e.g. index=sampledata src=* | head 10 | nsresolve src ip

Type: None | Splunk Version: 3.x | Author: gkanapathy More »
Screenshot

Splunk for OSSEC

Field extraction for OSSEC HIDS(http://www.ossec.net)

Type: Network Security | Splunk Version: 3.x | Author: elazar More »
Screenshot

Splunk for Change Management

Splunk for Change Management provides predefined reports and dashboards to facilitate change auditing, change detection, change reporting, change validation and incident response based on change events, change tickets and configuration files.

Type: Change Management | Splunk Version: 3.x | Author: Splunk More »
Screenshot

Splunk for Unix and Linux

Splunk for *nix provides pre-built data inputs, searches, reports, alerts and dashboards for Linux and Unix management. Now you can monitor, manage and troubleshoot *nix operating systems from one place with Splunk for *nix. Included are a set of scripted inputs for collecting CPU, disk, I/O, memory, log, configuration and user data. The app makes getting started with Splunk a breeze.

Type: Suite | Splunk Version: 4.x | Author: Splunk More »
Screenshot

Web Page Monitor

This bundle will check a set of webpages every interval and index the result, time, size and optionally content and or crc of page(s). It's cool to do searches to see when your pages change, take long to load, or many other cool things.

Type: None | Splunk Version: 4.x | Author: erik More »
Screenshot

Splunk for Windows for Splunk 3.x

Splunk for Windows application is a compilation of saved searches, eventtypes, inputs, and field extractions for Windows. The extractions are compatible with the Splunk Common Information Model. The application also contains an integration for Microsoft’s System Center Operations Manager.

Type: Windows | Splunk Version: 3.x | Author: Splunk More »
Screenshot

Splunk for Network Security

The Splunk Network Security application offers a set of reports, saved searches, and dashboards, as well as corresponding alerts that you can use to monitor your firewalls, intrusion detection and prevention systems, as well as operating systems.

Type: Network Security | Splunk Version: 3.x | Author: Splunk More »

Arkeia

Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.

Type: Change Management | Splunk Version: 3.x | Author: maverick More »
Screenshot

Splunk for CISCO PIX

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Type: Cisco PIX | Splunk Version: 3.x | Author: Splunk More »

Negative Searching Demo Bundle

This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.

Type: Compliance | Splunk Version: 3.x | Author: maverick More »

IPFW Firewall

This application contains field extractions and eventtypes for IPFW firewall log files.

Type: ipfw | Splunk Version: 3.x | Author: raffy More »
Screenshot

OpenBSD Packet Filter

This bundle contains field extractions and eventtypes for OpenBSD firewall events.

Type: Firewalls | Splunk Version: 3.x | Author: raffy More »

Nessus Bundle

This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.

Type: Nessus | Splunk Version: 3.x | Author: maverick More »

Splunk for Netscreen

This app provides field extraction and event types for Netscreen firewalls. The extractions are compatible with the Splunk common information model.

Type: Firewalls | Splunk Version: 3.x | Author: Splunk More »

Ironport field extractions

Provides file classification, date extraction, and extractions for ironport data.

Type: Ironport | Splunk Version: 3.x | Author: ssorkin More »

Brian's valgrind bundle

aggregates and extracts information from valgrind logs

Type: None | Splunk Version: 3.x | Author: BSplunk More »

Brian's crash report log bundle

Aggregates and extracts useful information from osx crash reporter logs.

Type: None | Splunk Version: 3.x | Author: BSplunk More »

adds support for anonymizing log files at index time

anonymizes ip address as 127.0.0.1 (localhost); email addresses as user@domain.com ; social-security-numbers as 555-00-0000; password/passwd looking values as 'password' ; username/userid/login/user looking values as 'bob'.

Type: Access and Identity Management | Splunk Version: 3.x | Author: carasso More »

Snort fields

Extracts snort 2.6 fields which can be used in reporting.

Type: Snort | Splunk Version: 3.x | Author: mfratto More »
Screenshot

Nmap Scripted Input & Field Extraction

Want to put your Nmap output into Splunk? Check out this add-on, which will parse your grepable Nmap output into a scripted input and then perform some field extraction on the data.

Type: Security Applications | Splunk Version: 3.x | Author: araitz More »

WebLogic Event Types

Field Extractions and Event Types that match events coming from WebLogic 9.2 and WebLogic 10.0.

Type: BEA WebLogic | Splunk Version: 3.x | Author: Splunk More »
Screenshot

OSX Battery Monitor

Bundle for monitoring battery usage on an OSX based laptop.

Type: Monitoring | Splunk Version: 3.x | Author: kordless More »

Checkpoint Event Field Extraction

Search-time parsing of following fields: loc, time, action, orig, i/f_dir, i/f_name, has_accounting, uuid, product, src, dst, proto, rule

Type: Checkpoint FW-1/VPN-1 | Splunk Version: 3.x | Author: goldburtd More »

What are Apps and Add-ons?

Apps give you insight into your IT systems with dashboards, reports, data inputs and saved searches that work in your environment from the moment they install. Save time and money with free plug-and-play solutions built by Splunk, our partners and users.

Add-ons let you tackle specific data problems directly. Built by Splunk partners and power users from the Splunk community, add-ons are smaller, reusable components that can change the look and feel of Splunk, add data sources or share information between users.

How Do I Get Them?

You can browse and install apps from the menu at left or through the App Launcher within your Splunk installation. Visit the Administration Manual to learn more about installing apps or add-ons.

Most Splunk apps and add-ons are completely free and work with both the Free and Enterprise versions of Splunk 4.x. If you're looking for apps for older versions of Splunk, visit the Splunkbase Archive.

Build Your Own

The Splunk developer framework makes it easy to turn your Splunk work into custom apps and add-ons. Read the Developer Manual to find out how.

Come back to Splunkbase when you're ready to show your app to the world and visit the Share page to upload your app to the Splunk community.