Github: https://github.com/mutedmouse/ELKomply
- Highly encourage pull requests and issues as well as suggestions for future implementations
ELKomply configs Github: https://github.com/mutedmouse/ELKomply_configs
- You are going to want these (and per platform guides) to take full advantage of ELKomply
This app is suitable for installation at any stage of your splunk architecture
disabling/enabling of features is highly recommended depending on installation location
FOR EXAMPLE:
- calculated fields and aliases are not necessary on INDEXERS but are required on SEARCH HEADS and ES NODES
This app currently requires two indexes to be created and accessible on INDEXERS:
- host (create with $SPLUNK_HOME/bin/splunk add index host)
- network (create with $SPLUNK_HOME/bin/splunk add index network
- This requirement will be removed in future releases
HEC Tokens are disabled by default on Splunk instance:
- Enable on Settings -> Data Inputs -> HTTP Event Collector -> Global Settings
- Select "Enabled"
- Deselect "Enable SSL"
HEC (HTTP Event Collectors) are not currently configured for https
- SSL HEC tokens are available but beyond the scope of this documentation
- https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Inputsconf#http:_.28HTTP_Event_Collector.29
- https://docs.splunk.com/Documentation/Splunk/latest/Security/Howtoself-signcertificates
- https://docs.splunk.com/Documentation/Splunk/8.1.0/Security/HowtoprepareyoursignedcertificatesforSplunk
Again a big thank you to:
- Splunk support team! (you know who you are)
- Chris Burch (packetsneaker@gmail.com)
- Everyone who downloads this or even giggles at the corny description, you make it worth it
Minor updates to parsing and eval statements (SecurityOnion 2.x / Suricata / Alert Category)
Major credit to Chris Burch (packetsneaker@gmail.com) for assistance in mapping data late into the night.
Big thank you to our Splunk support folks. None of this would be possible without an awesome staff and team.
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.