UTBox is a set of building blocks for Splunk specially created for URL manipulation. UTBox has been created to be modular, easy to use and easy to deploy in any Splunk environments. It only needs to be deployed on Splunk Search Heads and the bundles will automatically be sent to your Splunk Indexers. One of the core feature of UTBox is to correctly parse URLs and complicated TLDs (Top Level Domain) using the Mozilla Suffix List. Other functions like shannon entropy, counting, suites, meaning ratio, bayesian analysis, etc, are also available. UTBox has firstly be created for security analysts but may fit other needs as it's a set of building blocks. Enterprise Security users will need to modify the import statement to use UTBox. You should also take a look at URLParser for efficient URL parsing: https://splunkbase.splunk.com/app/3396/ 🐞 For assistance, create issue on: https://github.com/splunk/utbox/issues/new Maintainer: GSS FDSE @ Splunk Code Commiters: FDSE, Daniel, Mayur, Cedric, and Ian.
(0)
Categories
Created By
Contributors
Type
Downloads
Licensing
Splunk Answers
Resources