Skip to main content
Warning
This app is archived. App archiving documentation
Suricata app for splunk app icon

Suricata app for splunk

Welcome to the Suricata app for Splunk. This app contains field extraction for Suricata fast.log and separate field extraction for Suricata ssh.json log. Suricata ssh.json it's a separate log for only ssh events (all ssh events in your traffic).Built by Sergey Malinkin
splunk product badge

Default Version 1.0

June 22, 2016

Compatibility

Splunk Enterprise

CIM Version: 4.x

Rating
2
(3)

Log in to rate this app

Support
Archived App

Welcome to the Suricata app for Splunk. This app contains field extraction for Suricata fast.log and separate field extraction for Suricata ssh.json log. Suricata ssh.json it's a separate log for only ssh events (all ssh events in your traffic). Aslo in app you can find two dashboard. - First dashboard for analysis suricata fast.log - Second dashboad for visual analisis ssh.json log with function for flexible analysis by next field: data source, source and destination ip, server or client software, time.