Fields Apps

The Archive supports a collection of apps for Splunk prior to version 4.0. Browse the menu at left to find apps or add-ons by the category of solution they provide or the Splunk function they're built for. To learn more about installing apps in Splunk 3.x, check the Adminstration Manual for your version.

Want to custom-define fields in your events?

Field apps let you download field definitions to install in your Splunk server, or share fields you made yourself! Even better, an app can have more than one type of content, so you can add fields to any app.

Splunk for UNIX (Splunk 3 Compatible)

The Splunk for UNIX application is a compilation of a dashboard, saved searches, eventtypes, and field extractions that work for various flavors of UNIX. In addition, the application also ships with a set of scripted inputs that can be used to monitor UNIX machines. Inputs like top, ps, vmstat, iptables, and netstat, are supported.

Splunk for OSSEC

Field extraction for OSSEC HIDS(http://www.ossec.net)

Splunk for Windows for Splunk 3.x

Splunk for Windows application is a compilation of saved searches, eventtypes, inputs, and field extractions for Windows. The extractions are compatible with the Splunk Common Information Model. The application also contains an integration for Microsoft’s System Center Operations Manager.

Splunk Version: 3.x | Author: Splunk | Category: More »

Arkeia

Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.

Splunk for CISCO PIX

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Splunk Version: 3.x | Author: Splunk | Category: More »

IPFW Firewall

This application contains field extractions and eventtypes for IPFW firewall log files.

Splunk Version: 3.x | Author: raffy | Category: More »

OpenBSD Packet Filter

This bundle contains field extractions and eventtypes for OpenBSD firewall events.

Splunk Version: 3.x | Author: raffy | Category: More »

Nessus Bundle

This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.

Splunk for Netscreen

This app provides field extraction and event types for Netscreen firewalls. The extractions are compatible with the Splunk common information model.

Splunk Version: 3.x | Author: Splunk | Category: More »

Ironport field extractions

Provides file classification, date extraction, and extractions for ironport data.

Splunk Version: 3.x | Author: ssorkin | Category: More »

adds support for anonymizing log files at index time

anonymizes ip address as 127.0.0.1 (localhost); email addresses as user@domain.com ; social-security-numbers as 555-00-0000; password/passwd looking values as 'password' ; username/userid/login/user looking values as 'bob'.

Snort fields

Extracts snort 2.6 fields which can be used in reporting.

Splunk Version: 3.x | Author: mfratto | Category: More »

Nmap Scripted Input & Field Extraction

Want to put your Nmap output into Splunk? Check out this add-on, which will parse your grepable Nmap output into a scripted input and then perform some field extraction on the data.

Splunk Version: 3.x | Author: araitz | Category: More »

WebLogic Event Types

Field Extractions and Event Types that match events coming from WebLogic 9.2 and WebLogic 10.0.

OSX Battery Monitor

Bundle for monitoring battery usage on an OSX based laptop.

Splunk Version: 3.x | Author: kordless | Category: More »

Checkpoint Event Field Extraction

Search-time parsing of following fields: loc, time, action, orig, i/f_dir, i/f_name, has_accounting, uuid, product, src, dst, proto, rule

Splunk Version: 3.x | Author: goldburtd | Category: More »

Watchguard Firebox

Field Extractions for Watchguard Firebox

Splunk Version: 3.x | Author: araitz | Category: More »

WebLogic Access

Field Extractions for WebLogic HTTP Access Logs

Splunk Version: 3.x | Author: vly | Category: More »

Postfix main.cf field extractions

This Add-on extracts fields related to useful troubleshooting and configuration from the Postfix main.cf configuration file.

twiki logs

Contains the basic extractions as well as some saved searches, reports, event types, and custom dashboard modules.

Splunk Version: 3.x | Author: nick | Categories: More »

Bladelogic NSH and Agent Logs

This bundle contains field extractions for the Bladelogic agent and nsh log files. Some sample reports are also included.

Sonicwall Firewall

This bundle performs field extractions for sonicwall TZ 170 without the UTM/IDS modules

Exchange fields and inputs

This add-on applies to Microsoft Exchange event tracking logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk's_interface_standards).

Netcache fields, inputs, and event types

This add-on normalizes Netcache fields so that other Splunk applications understand them.

Sendmail fields, inputs, and event types

This add-on applies to Sendmail logs, bringing their field names into compliance with the Splunk interface standard (see http://www.splunkbase.com/howtos/Splunk/howto:Understanding_Splunk's_interface_standards).