All Searches Applications

Want to share searches?

Search Applications allow you to download Splunk searches other people have created, or to share ones you've made! Even cooler, an Application can have more than one type of content, so you can add searches to any Application.

Not a Splunk user? Download Splunk, set up your Splunk server, and then install your Applications(s) to extend your server.

More...

Screenshot

AfterGlow Graphing

This new search processor enables the generation of link graphs through Splunk. Make sure you follow the instructions in the README (once installed, located in etc/apps/afterglow) to configure the application!

Author: raffy Type: Searches, Search Commands, Event Actions
Rating:
(3 votes)
Added: 14 months ago
Downloads: 2,264 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for IMAP

This application will continually download mail from an imap account where it is indexed by a splunk server. You can do cool things like see how often you get mail from someone, graph by size, time, etc.

Author: erik Type: Searches, Scripted Inputs, Inputs
Rating:
(3 votes)
Added: 14 months ago
Downloads: 499 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:

Splunk License Usage

This bundle provides a new dashboard which has several widgets that query to help you determine your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.

Author: joshs Type: Searches, Reports, Other
Rating:
(4 votes)
Added: 4 months ago
Downloads: 396 Last Updated: 4 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for UNIX

The Splunk for UNIX application is a compilation of a dashboard, saved searches, eventtypes, and field extractions that work for various flavors of UNIX. In addition, the application also ships with a set of scripted inputs that can be used to monitor UNIX machines. Inputs like top, ps, vmstat, and netstat are supported.

Author: Splunk Type: Searches, Scripted Inputs, Inputs, Fields, Event Types
Rating:
(4 votes)
Added: 9 months ago
Downloads: 24,097 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for PCI

The Splunk PCI application offers over 57 reports, more than 91 saved searches, a dashboard, and corresponding alerts you can use to satisfy PCI requirements such as secure remote access, file integrity monitoring, secure log collection, daily log review, audit trail retention, and PCI control reporting.

Author: Splunk Type: Searches, Reports, Event Types, Alerts
Rating:
(6 votes)
Added: 9 months ago
Downloads: 1,716 Last Updated: 17 hours ago
License: 30 Day Trial Price: Email sales@splunk.com for pricing
Categories:
Screenshot

Splunk for Change Management

Splunk for Change Management provides predefined reports and dashboards to facilitate change auditing, change detection, change reporting, change validation and incident response based on change events, change tickets and configuration files.

Author: Splunk Type: Searches, Reports, Inputs, Fields, Event Types, Event Actions, Alerts
Rating:
(5 votes)
Added: 7 months ago
Downloads: 674 Last Updated: 4 days ago
License: 30 Day Trial Price: Email sales@splunk.com for pricing
Categories:

Arkeia

Arkeia Network Backup Bundle used to index the common fields from the backup log file to make searching and reporting easier.

Author: maverick Type: Transactions, Searches, Reports, Fields, Event Types
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 92 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for CISCO PIX

Cisco PIX firewall log bundle that indexes and extracts common fields, normalizing PIX firewall logs so they are Splunk-compliant and will work with other Splunk applications.

Author: Splunk Type: Searches, Reports, Fields, Event Types
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 1,555 Last Updated: 1 month ago
License: Creative Commons Price: Free
Categories:

Negative Searching Demo Bundle

This bundle, created jointly by Maverick and Stephen Sorkin, demonstrates a way to perform negative searches by indexing known patterns and catching anomalous patterns into a separate index.

Author: maverick Type: Searches, Reports, Inputs, Fields, Alerts
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 237 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

Nessus Bundle

This bundle extracts the common fields from a Nessus Vulnerability Scanner log file, such as the hostname, port, script id, and type.

Author: maverick Type: Fields, Alerts, Reports, Searches
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 358 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

nscreen

This bundle is for field extraction and reporting on netscreen firewalls

Author: jon Type: Fields, Searches
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 531 Last Updated: 7 months ago
License: Creative Commons Price: Free
Categories:

Brian's valgrind bundle

aggregates and extracts information from valgrind logs

Author: BSplunk Type: Fields, Searches
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 16 Last Updated: 12 months ago
License: Creative Commons Price: Free
Categories:
None

steveyz_bundle

A few useful searches leveraging the monitoring bundle data, using the multikv operator

Author: steveyz Type: Searches, Reports
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 87 Last Updated: 14 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Web Page Monitor

This bundle will check a set of webpages every interval and index the result, time, size and optionally content and or crc of page(s). Its cool to do searches to see when your pages change, take long to load, or many other cool things.

Author: erik Type: Searches, Scripted Inputs, Inputs, Fields
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 932 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:

Linux Failed Login

A series of saved searches to detect common login failures on Linux hosts.

Author: m@ Type: Searches
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 456 Last Updated: 7 months ago
License: Creative Commons Price: Free
Categories:

Eggdrop IRC

A simple bundle to parse channel name, action status & msg, and user nick out of Eggdrop IRC channel logs.

Author: amrit Type: Searches
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 32 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

SplunkWidget

Widget for the OS X Dashboard to list your saved searches and alerts. Double click on the uncompressed SplunkWidget to install, see the README.txt file for more info. Requires OS X Tiger, 10.4.3+

Author: andrea Type: Searches, Clients, Alerts
Rating: Awaiting 3 votes Added: 14 months ago
Downloads: 181 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

Splunk internal front end development bundle

This bundle right now just implements a simple dashboard to keep track of some simple Front end things around the Splunk interface itself. Searches on this dashboard show last-24-hours charts of - Splunk logins, splunk searches executed, indexing throughput, and longest query time. NOTE: this bundle is more notable probably because it shows how you can bundle a dashboard. HOWEVER the configuration for dashboards will still undergo a very significant amount of change, so beware that this area will require more maintenance than most... =)

Author: nick Type: Searches
Rating: Awaiting 3 votes Added: 13 months ago
Downloads: 67 Last Updated: 13 months ago
License: Creative Commons Price: Free
Categories:

twiki logs

Contains the basic extractions as well as some saved searches, reports, event types, and custom dashboard modules.

Author: nick Type: Searches, Reports, Fields, Event Types, Event Actions
Rating: Awaiting 3 votes Added: 11 months ago
Downloads: 106 Last Updated: 7 months ago
License: Creative Commons Price: Free
Categories:

Splunk Parse

Splunk Parse (splunk_parse.py) is a python script you can set as your alert action on a saved search. It reads in the fields a saved search passing along and parses the corresponding saved search log file which is in CSV format. The parsing spits out the originating host and the full original problem. In this version it's feed to my ticketing system, but the output action can be easily changed.

Author: shaggy Type: Searches, Integration, Custom Processing, Alerts
Rating: Awaiting 3 votes Added: 7 months ago
Downloads: 106 Last Updated: 7 months ago
License: Creative Commons Price: Free
Categories:

Splunk License Usage

This bundle provides a new dashboard which has several widgets that query to help you determine your Splunk license usage total over the past 24 hours as well as usage by host, source, and sourcetype. It contains timecharts to help you understand usage over time and see usage spikes as well as pie charts to help you to figure out which log files, sourcetypes, and hosts Splunk is indexing the most data from.

Author: joshs Type: Searches, Reports, Other
Rating: Awaiting 3 votes Added: 4 months ago
Downloads: 396 Last Updated: 4 months ago
License: Creative Commons Price: Free
Categories:

Splunk Alert

Command line utility to more easily search the splunk database, log specific errors and execute commands on a match. Comes with several predefined searches for cisco networking, and is easily extended. -s search Predefined search to run, use 'list' for options -cs string Custom search string passed in with quotes -l file Log results to file, appends by default -e email_addr Email addresses comma separated -x command Execute a command on a match -t time_restrict Suppress email alerts by time of day, use 'list' for options -d days Search over this many days in the past (default: 1) -m minutes Search over this many minutes in the past -c maxnum Max number of results (default: 100) -r Reverse results, (newest to oldest) -w Raw results, do not strip off timestamps -q Quiet Output, suppress errors -v Verbose output

Author: yantisj Type: Searches, Event Actions, Custom Processing, Alerts
Rating: Awaiting 3 votes Added: 6 months ago
Downloads: 249 Last Updated: 6 months ago
License: Creative Commons Price: Free
Categories:

Splunk Assist Application

The Splunk assist application is to be used for troubleshooting, monitoring, and enhancing the performance of Splunk. The application contains a group of files that contains searches and configuration options that will assist in your use of Splunk.

Author: Splunk Type: Searches, Reports
Rating: Awaiting 3 votes Added: 5 months ago
Downloads: 243 Last Updated: 2 months ago
License: Creative Commons Price: Free
Categories:
Screenshot

Splunk for Citrix XenServer Management

This Splunk application manages Citrix XenServers. It includes inputs, indexing, searches, reports, dashboards and field actions.

Author: Splunk Type: Searches, Search Commands, Scripted Inputs, Inputs, Fields, Event Types
Rating: Awaiting 3 votes Added: 5 months ago
Downloads: 244 Last Updated: 4 months ago
License: Creative Commons Price:
Categories: