This add-on provides prebuilt configurations to collect, normalize, and index logs from Security Onion into Splunk. It supports key data sources such as Suricata, Zeek, Wazuh, and other Security Onion components. Key Features:
Preconfigured inputs for Security Onion log types
Field extractions and CIM-compatible tagging
Easy integration with Splunk DB Connect for enriched data analysis
Lightweight, ready-to-use for Splunk Enterprise and Cloud
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.