An Splunk technology add-on for osquery
osqueryd.INFO, osqueryd.WARNING, osqueryd.ERROR
osqueryd.results.log
osqueryd.snapshots.log
default/inputs.conf
First release base feature set populates datamodels:
Alerts Data Model base on alerts from packs
Changes Data Model base on FIM events from packs
Endpoint Data Model base on Splunks Query Pack
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.