Default Version 1.0
June 22, 2016
June 22, 2016
Splunk Enterprise
CIM Version: 4.x
Log in to rate this app
Welcome to the Suricata app for Splunk. This app contains field extraction for Suricata fast.log and separate field extraction for Suricata ssh.json log. Suricata ssh.json it's a separate log for only ssh events (all ssh events in your traffic). Aslo in app you can find two dashboard. - First dashboard for analysis suricata fast.log - Second dashboad for visual analisis ssh.json log with function for flexible analysis by next field: data source, source and destination ip, server or client software, time.
Log in to report this app listing.