Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Splunk Search Analyzer #97

Open
SivaPrem opened this issue Sep 21, 2017 · 17 comments
Open

Splunk Search Analyzer #97

SivaPrem opened this issue Sep 21, 2017 · 17 comments
Labels
category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related status:in progress

Comments

@SivaPrem
Copy link

Request Type
Feature Request

Hello All,
Thanks for the good work team , and the HIVE comes very handy to use in our SOC , I saw your presentation recently on CORTEX and the possibility to have Splunk Search option in the analyzer

Would like to know in which version it was planned to be added

If available it would be very good

Merci ....................

@SivaPrem SivaPrem changed the title Splunk Search Functionality Splunk Search Analyzer Oct 8, 2017
@Status-418
Copy link

+1

@saadkadhi saadkadhi added scope:analyzer Issue is analyzer related category:feature-request Issue is related to a feature request help wanted labels Oct 11, 2017
@saadkadhi
Copy link
Contributor

Hi @SivaPrem. We haven't gotten around to develop one yet and hopefully we'll be able to in the not-so-long term. We can't provide a date currently. We'll update the issue as soon as we can.

@BrevilleBro
Copy link

Hi,

We have developed a Splunk analyser. We will need to do some cleanup for public release, but hopefully will be able to release it in the coming week or two.

@SivaPrem
Copy link
Author

@saadkadhi : Thank you very much , U guys rock , Missed Hack.lu / Misp Summit

@SivaPrem
Copy link
Author

@BrevilleBro : Wow , thats amazing , Looking forward to it

@saadkadhi
Copy link
Contributor

Excellent @BrevilleBro. I'll change the label to in progress.

@BrevilleBro
Copy link

BrevilleBro commented Nov 13, 2017

Hi,

Just keeping everyone updated. We are currently preparing the analyzer for release (next day or two). We will strip it back to a 'bare-bones' Splunk Search for compatibility, however, if anyone wants an example/release of a more environment specific Splunk Search (i.e., proxy logs), please let me know.

@SivaPrem
Copy link
Author

@BrevilleBro : Perfect , thats good news !!!!! search on proxy logs will be amazing to have it !!!!!

@BrevilleBro
Copy link

BrevilleBro commented Nov 21, 2017

Hi,

We have released our Splunk analyser. @SivaPrem , let us know if you encounter any issues :)
https://github.com/UNIT777/Cortex-Analyzers/tree/Splunk

I have included a generic template/analyzer template, as well as more specific ones (although they may need to be customised to your environment).

@SivaPrem
Copy link
Author

@BrevilleBro :: Awesome !!!! Thanks for the efforts ... I am gonna test it today !! will update you

@saadkadhi
Copy link
Contributor

Thanks @BrevilleBro for your contribution. @SivaPrem please let us know how it goes and we'll add it to the next release if everything is OK.

@Edward-merrett
Copy link

Any update on the next release? Can you help me with how I get this installed on my env now please? How to I add this to the current analyzers folder and theHive?

@ghost
Copy link

ghost commented Nov 6, 2018

Any update available?

@LetMeR00t
Copy link
Contributor

Hi,
Do you still need help on this guys ?
Thank you

@LetMeR00t
Copy link
Contributor

Hello everyone,
A new version of the analyzer was proposed here : #534

Thank you

@cbboggs
Copy link

cbboggs commented Dec 4, 2019

@LetMeR00t taking a look at your analyzer, but couldn't find any documentation beyond what is in the configuration options... is there some help/docs out there somewhere?

@LetMeR00t
Copy link
Contributor

Hi @cbboggs,
The concerned PR for the documentation is here : TheHive-Project/CortexDocs#44

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
category:feature-request Issue is related to a feature request scope:analyzer Issue is analyzer related status:in progress
Projects
None yet
Development

No branches or pull requests

7 participants