Latest Version 1.0.1
September 12, 2024
Pulls down Thinkst Canary audit logs using the API. Install on Splunk Cloud IDM or a heavy forwarder. Can also be installed on Search heads for the sourcetypes, but its clearer if you just create the sourcetype canarytools:audit manually with KV_MODE = none. Icon from https://www.vecteezy.com/vector-art/1919479-linear-audit-document-icons-design-isolated-on-white-background https://github.com/Bre77/TA_thinkst_canary_audit
(0)
Categories
Created By
Source Code
Type
Downloads
Licensing
Splunk Answers
Resources