Welcome to the new Splunkbase! To return to the old Splunkbase, .
Warning

This app is archived.

ELKomply app icon

ELKomply

If you have one or more of the following symptoms you may be tired of ELK: - Getting exasperated at elasticsearch management? - Feeling groggy at grokking? - Getting crabby at kibana? - Feeling suffocated by so many separate SIEMS? - Haunted by hunting in lucene?

Built by
splunk product badge

Latest Version 1.0.3
December 1, 2020
Compatibility
Not Available
Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 4.x
Rating

0

(0)

Log in to rate this app
Support
ELKomply support icon
Not Supported
If you have one or more of the following symptoms you may be tired of ELK: - Getting exasperated at elasticsearch management? - Feeling groggy at grokking? - Getting crabby at kibana? - Feeling suffocated by so many separate SIEMS? - Haunted by hunting in lucene? Well, ELKomply is here to help. By implementing customized Logstash http output filters to a Splunk HEC receiver (derived from open source elastic forums) you can get real time data fed straight from Logstash instances in your existing open-source SIEM infrastructure fed directly into Splunk ecosystem. Not only that, but no more having to reingest data just to extract that new field you wanted or fighting your way through multi-index searching sorcery. Wish ALL your data mapped to one CIM? So did we, and now it is (or soon will be)! One day you may event be able to turn off those Elasticsearch instances and hunt those data feeds completely in Splunk. Discerning Splunkers may ask "but it this Enterprise Security compliant?" You can bet your hot buckets it is and always will be! So come on down and let ELKomply help ease your transition to a better hunt? ELKomply receives logs from ELK based platforms via HEC event tokens and preconfigured Logstash pipeline configuration files provided on accompanying github repository (https://github.com/mutedmouse/ELKomply_configs). This app utilizes field aliases, extractions, calculated fields, and lookups to normalize data from host and network monitoring solutions to the latest CIM for compliance with Enterprise Security. Currently the priority of effort is getting SecurityOnion 2.x data mapped over and then adding additional platforms and mapped datamodels. Please check https://github.com/mutedmouse/ELKomply for out-of-band updates and non-release versions. Thank you to everyone named and not who made and supported this effort. You are the real heroes here.

Categories

Created By

Andrew Quill

Type

app

Downloads

443

Splunk Answers

Resources

Log in to report this app listing