Skip to main content
Warning
This app is archived. App archiving documentation
Snort 3 JSON Alerts app icon

Snort 3 JSON Alerts

This repository is a Technology Add-On for Splunk that allows you to ingest IDS alerts into Splunk from Snort 3 in json format. This plugin normalizes these alerts conform to the "Intrusion Detection" model in the Splunk Common Information Model (CIM), and can be accessed within any app or dashboard that reports Intrusion Detection events.Built by Noah Dietrich
splunk product badge

Default Version 1.0.5

October 23, 2023

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x, 3.x

Rating
5
(2)

Log in to rate this app

Support
Archived Add-on

This repository is a Technology Add-On for Splunk that allows you to ingest IDS alerts into Splunk from Snort 3 in json format. This plugin normalizes these alerts conform to the "Intrusion Detection" model in the Splunk Common Information Model (CIM), and can be accessed within any app or dashboard that reports Intrusion Detection events.