Splunk App for Enterprise Security
A single solution to detect known threats and look for unknown threats through analysis of massive volumes of activity data.
Comparing week-over-week results is a pain in Splunk. You have to do absurd math for crazy date calculations. No more. I wrote a convenient search command called "timewrap" that does it all, for arbitrary time periods. Compare week-over-week, day-over-day, month-over-month, quarter-over-quarter, year-over-year, or any multiple (e.g. two week periods over two week periods). Just add "| timewrap 'time-span'" after a 'timechart' command, where time-span is something like 'h' (hour), 'w' (week), 'm' (month), 'q' (quarter), 'y' (year).
Splunk Add-on for Microsoft Windows
The Splunk for Microsoft Windows add-on includes predefined inputs to collect data from Windows systems and maps to normalize the data to the Common Information Model.