Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
Warning

This app is archived. Learn more

TA For SplunkStart Basic Security Essentials for Splunk app icon

TA For SplunkStart Basic Security Essentials for Splunk

This TA is an add-on for the SplunkStart app hosted on Splunkbase. It has two key Security Essentials searches (First Time Seen and Time Series Outlier) that you can use with YOUR own data by simply editing a form on SplunkStart to use your own index, sourcetype, and field names. First install SplunkStart. Then, download this TA and gunzip/untar (tar -zxvf) it somewhere on the same machine as SplunkStart. The TA does not need to be in $SPLUNK_HOME/etc/apps. Next cd into the SplunkStart/bin directory and execute the create_content.sh and it will copy the contents of this TA to SplunkStart. For complete details, read the README.txt or the details section of this TA. Note: In the default dashboard for this TA, version="1.1" was added to the top of the file in the dashboard tag for cloud compatibility. The previous tag defaulted to version="1.0"

Built by Splunk Works
splunk product badge
screenshot

Latest Version 1.0.2
May 6, 2022
Compatibility
Not Available
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1
Rating

0

(0)

Log in to rate this app
Support
TA For SplunkStart Basic Security Essentials for Splunk support icon
Not Supported
This TA is an add-on for the SplunkStart app hosted on Splunkbase. It has two key Security Essentials searches (First Time Seen and Time Series Outlier) that you can use with YOUR own data by simply editing a form on SplunkStart to use your own index, sourcetype, and field names. First install SplunkStart. Then, download this TA and gunzip/untar (tar -zxvf) it somewhere on the same machine as SplunkStart. The TA does not need to be in $SPLUNK_HOME/etc/apps. Next cd into the SplunkStart/bin directory and execute the create_content.sh and it will copy the contents of this TA to SplunkStart. For complete details, read the README.txt or the details section of this TA. Note: In the default dashboard for this TA, version="1.1" was added to the top of the file in the dashboard tag for cloud compatibility. The previous tag defaulted to version="1.0"

Categories

Created By

Splunk Works

Contributors

Nimish Doshi

Type

addon

Downloads

1,430

Resources

Login to report this app listing