Splunk App for Enterprise Security
A single solution to detect known threats and look for unknown threats through analysis of massive volumes of activity data. Splunk App for Enterprise Security is a scalable security intelligence platform with the flexibility to make tens of terabytes of data per day security relevant through comprehensive analysis capabilities that breaks down organizational data silos and data collection issues. * Situational awareness dashboards give custom views of risk per domain, asset, or identity * Incident Review provide analysis workflows that reveal the priority of the incident, incident context, and impact on assets and identities * Analysis centers provide indicators of unknown threats from traffic abnormalities * Correlation tools enable monitoring for new attackers by correlating new domain registration with web activity * Statistical outlier detection tools aid anomaly detection * Unified Threat Intelligence from many sources * Data inputs provided for NetFlow, logs, RDBMS, APIs, & more
Hurricane Labs Firewall App
Splunk® 6 ONLY The Hurricane Labs(www.hurricanelabs.com) Firewall app for Splunk® Enterprise utilizes Check Point(TM) sources to access, view and monitor your Check Point data. This app is not support by Splunk and will only be supported on a best effort basis by Hurricane Labs. We hope you find it useful and as always we welcome any constructive feedback. Prerequisites: Installation and configuration of the Splunk Add-on for Check Point OPSEC LEA Linux (http://apps.splunk.com/app/1454/) is required. Features: - Provides general overview information of your Check Point environment. - Check Point IPS Overview. - Check Point IPS Performance Impact including the ability to narrow down your data by Firewall, Performance Impact Level and Confidence Level - Check Point VPN information. Check Point is a registered trademark of Check Point Software Technologies Ltd.
Splunk App for Unix and Linux
The Splunk App for Unix and Linux provides rapid insights and operational visibility into large-scale Unix and Linux environments. With its new pre-packaged alerting capability, flexible service-based hosts grouping, and easy management of many data sources, it arms administrators with a powerful ability to quickly identify performance and capacity bottlenecks and outliers in Unix and Linux environment. The Splunk App for Unix and Linux is easy to deploy and comes with configurable data inputs allowing you to quickly provision new Unix and Linux hosts and services. The Splunk App for Unix and Linux is compatible with Splunk 5.x and 6.x. The Splunk App for Unix and Linux is not supported on any version of Internet Explorer because it makes heavy use of scalable vector graphics (SVG), a standard for which IE has limited support. It can, however, be used on any other Splunk-supported browser.