|Author||Aplura, LLC. Corelight, Inc.|
|Vendor Products||Corelight Sensor|
|Has index-time operations||false|
|Creates an index||false|
|Implements summarization||Currently, the app does not generate summaries|
About Corelight For Splunk
Corelight For Splunk allows a Splunk Enterprise administrator to extract information and knowledge from Bro data via the Corelight Sensor appliance or open-source Bro
This App provides the following scripts:
Version 1.0.3 of Corelight For Splunk is compatible with:
|Splunk Enterprise versions||6.6, 7.0|
Version 1.0.3 of Corelight For Splunk has the following known issues:
Access questions and answers specific to Corelight For Splunk at https://answers.splunk.com . Be sure to tag your question with the App.
Support is available via email at firstname.lastname@example.org. Responses vary on working days between working hours. Find the latest information about the App and integration on the support website.
Because this App runs on Splunk Enterprise, all of the Splunk Enterprise system requirements at https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements apply.
Download Corelight For Splunk at https://splunkbase.splunk.com/.
NOTE: Where referenced, TA-CorelightForSplunk is located on Splunkbase.
Follow these steps to install the app in a single server instance of Splunk Enterprise:
By default all events will be written to the main index. Please see Corelight documentation on how to change the destination index from the appliance.
By default, all corelight information is searched for using the corelight_idx event type. To change the location for the app to search for Corelight data, edit the corelight_idx event type to point to your Corelight index.
Corelight For Splunk contains several lookup files.
Corelight For Splunk does make use of an event generator. This allows the product to display data, when there are no inputs configured.
The stanzas are:
Fixes the HTTP Panel, much faster.
Adds support for Corelight Reduced logging.
Bug Fixes, increase performance of dashboards.
Search optimizations and bug fixes
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.