The GreenZone Splunk Healthcheck app provides health monitoring and CIM compliance assessment capabilities for Splunk Enterprise Security deployments. The app connects remotely to Enterprise Security search heads to query CIM tag coverage across sourcetypes and indexes, caching the results for dashboard-based visualization and analysis. It includes custom search commands that communicate with the Enterprise Security management API to retrieve data model coverage information and scheduled searches that maintain cached lookup tables of CIM tag compliance metrics. The app is designed for deployment on Monitoring Console instances or dedicated search heads that perform centralized health checks of remote Enterprise Security installations, enabling administrators to track data source normalization and CIM adoption across their environment.
Categories
Utilities, SIEM
Contributors
Sivaranjini Ganesan
Resources
Log in to report this app listing