Application provides parsing fixes for various technologies. It is recommended to install this application with Infigo SIEM application in order to get maximum from your SIEM. Additional parsing and mapping to CIM are most notably done for Sysmon, Cisco eStreamer, Splunk Stream DNS, MS Defender.
Keep in mind that for some specific sourcetypes it reduces the size of events, examples are Fortigate and Palo Alto, Checkpoint, Windows.
Also it provides full sourcetypes parsing for some less known technologies like Dell EMC, Clavister, HP and Fujitsu Backups.
Application provides parsing fixes for various technologies. It is recommended to install this application with Infigo SIEM application in order to get maximum from your SIEM. Additional parsing and mapping to CIM are most notably done for Sysmon, Cisco eStreamer, Splunk Stream DNS, MS Defender.
Keep in mind that for some specific sourcetypes it reduces the size of events, examples are Fortigate and Palo Alto, Checkpoint, Windows.
Also it provides full sourcetypes parsing for some less known technologies like Dell EMC, Clavister, HP and Fujitsu Backups.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.