AppOmni Splunk App
The AppOmni Splunk App is an app containing two sourcetypes (appomni_alerts & appomni_workflow), it also has a number of dashboards looking at events/alerts sent from the AppOmni event sink, and one policy overview dashboard looking at policy violations sent from a workflow.
Both sourcetypes are ingesting the JSON data, but have some slight parsing differences. The appomni_alerts parses the data sent from the AppOmni Event Sinks, while the appomni_workflow sourcetype parse the data from AppOmni notification workflows.
The data parsed by appomni_alerts and appomni_workflows can be sent into the same index or different indexes depending on your desired retention. The indexes the data is sent to needs to be referenced in the macros which are used by the dashboards. To update the indexes reference in the macros. Navigate to Settings>Advanced Search>Search Macros
Open the macro and populate the index for appomni_macro (events from AppOmni Event Sink will go here) and the workflow_macro (events from the AppOmni workflow notifications will go here).
IMPORTANT. After creating a workflow, contact your AppOmni representative and let them know you want your workflow sent in a “flattened format”.
If you like to keep both alerts and workflow in the same index, populate the macros with the same index.
Corrected background image reference from KV store to local directory.
Corrected some SPL.
Added Splunk Dashboard Studion Dashboards and kept all the old Simple XML dashboards all available under Dashboards.
ACEs Schema Documentation
https://labs.appomni.com/aces/OVERVIEW.html
SaaS Event Maturity Matrix
https://eventmaturitymatrix.com/#appomni-audit-logs
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.