|Author||Aplura, LLC. Corelight, Inc.|
|Vendor Products||Corelight Sensor|
|Has index-time operations||false|
|Creates an index||false|
|Implements summarization||Currently, the app does not generate summaries|
About Corelight For Splunk
Corelight For Splunk allows a Splunk Enterprise administrator to extract information and knowledge from Bro data via the Corelight Sensor appliance or open-source Bro
This App provides the following scripts:
Version 1.0.0 of Corelight For Splunk is compatible with:
|Splunk Enterprise versions||6.6, 7.0|
Version 1.0.0 of Corelight For Splunk has the following known issues:
Access questions and answers specific to Corelight For Splunk at https://answers.splunk.com . Be sure to tag your question with the App.
Support is available via email at firstname.lastname@example.org. Responses vary on working days between working hours. Find the latest information about the App and integration on the support website.
Because this App runs on Splunk Enterprise, all of the Splunk Enterprise system requirements at https://docs.splunk.com/Documentation/Splunk/latest/Installation/Systemrequirements apply.
Download Corelight For Splunk at https://splunkbase.splunk.com/.
NOTE: Where referenced, TA-CorelightForSplunk is located on Splunkbase.
Follow these steps to install the app in a single server instance of Splunk Enterprise:
By default all events will be written to the main index. You should change the index in the configuration files to match your specific index.
Corelight For Splunk contains several lookup files.
Corelight For Splunk does make use of an event generator. This allows the product to display data, when there are no inputs configured.
The stanzas are:
Version 1.0.0 of Corelight For Splunk incorporates the following Third-party software or third-party services.
Please see full README inside the app.
Initial Release of Corelight App. Corelight For Splunk allows a Splunk Enterprise administrator to extract information and knowledge from Bro data via the Corelight Sensor appliance or open-source Bro.
Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.