icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Splunk Reference App - PAS
SHA256 checksum (splunk-reference-app-pas_152.tgz) 61c15c21ffc8c90b6efd3961c05c9b513b089f64da5327d2269ae864cb38a267 SHA256 checksum (splunk-reference-app-pas_150.tgz) aff355c07c9f5dfda52c66b7bdbb740a3bd7faae333462f2363eb27165312dd8 SHA256 checksum (splunk-reference-app-pas_101.tgz) 8957b9d1b4f0d7e934f64b43aeff9f9878164526aefc50dc2a012a0402762d88 SHA256 checksum (splunk-reference-app-pas_100.tgz) 20a73800e88a5a0448da55adad90c18b959cda98a49edf78476d238fcb3015aa
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Splunk Reference App - PAS

Splunk Cloud
Splunk Labs
This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
The Splunk Reference App will help you to learn how to build, test and deploy apps and solutions on Splunk. It is intended to showcase the proven practices and the Splunk Developer Platform which enables you to take advantage of the same underlying technologies that power the core Splunk Enterprise product.

The Pluggable Auditing System (PAS) is intended to enable an organization to monitor various document repositories (current and future). Managers and auditors can use the app to see who has viewed, modified, deleted, or downloaded documents or other artifacts from various sources, detect suspicious behaviors and analyze trends.

Contains: examples, guidance, sample code.

The Splunk Reference App - PAS teaches you how to develop apps for Splunk. Here, you can explore the evolution of the reference app along with some additional engineering artifacts, like tests, deployment considerations, and tradeoff discussions.

The accompanying Splunk Developer Guide for Building Apps presents a documentary of how the team went about building this reference app. The guide is currently available as a public preview. We welcome your feedback on both the app and the guide.

What Does This App Do?

The PAS app is intended to enable an organization to monitor various document repositories (current and future). Managers and auditors can use the app to see who has viewed, modified, deleted, or downloaded documents or other artifacts from various sources.

Requirements

Here's what you need to get going with the Splunk Reference App - PAS.

Splunk Enterprise

If you haven't already installed Splunk Enterprise, download it at
. For more information about installing and
running Splunk Enterprise and system requirements, see the
Installation Manual.

The main PAS app

Install or symlink the main app (pas_ref_app) to the $SPLUNK_HOME/etc/apps folder. For linking, use the ln command on Unix/MacOS or the mklink command on Windows.

Getting data in

There are several ways for you to feed data into the PAS app.

  • Ingest your own data. Just make sure those sources are tagged with "change" and "audit",

  • Use the eventgen app, if you want a simulated data flow. Get it from (note: it may take several minutes before the events start to be generated), or

  • Consume the test data set provided in the test repo.

Install dependencies

The reference app relies on data provider add-ons. Three simulated data providers (file add-on, documents application add-on, database add-on) and one real data provider (Google Drive Data Provider add-on) are made available. Install at least one data provider. You'll find the install scripts for Unix/MacOS and Windows in the /bin folder. For the Google Drive data provider installation and configuration, see specific instructions in the googledrive_addon/README folder.

The reference app uses a lookup table which could have been produced by an HR system process. For demonstration purposes, we have encapsulated it in the pas_hr_info add-on.

(Optional) Certain reference app functionality requires an identity provider. We have used a simulated identity provider.

Configure user access

Create a new user that belongs to the pasadmin or pasuser role, and log in as this new user.

Alternatively, add index 'pas' to the default searchable indexes by going to Splunk Settings -> Access controls -> Role -> admin -> Indexes searched by default and adding 'pas' into the list of default search indexes.

Note: if you are using a Splunk Free license, integrated role-based access control is not available.Thus, you will not be able to add new users or roles and should use the alternative method of adding the pas to the list of indexes searched by default.

Configure the app using the Setup page

Specify at least one department that you want to surface on the Summary dashboard.

Usage

For usage see the About page of the app.

Community and Feedback

Questions, comments, suggestions? To provide feedback about this release, to get help with any problems, or to stay connected with other developers building on Splunk please visit the community site.

File any issues on GitHub.

Community contributions via pull requests are welcomed! Go to the
Open Source page for more information.

Also contains (for discoverability)

Examples, sample code, tests, demo

Release Notes

Version 1.5.2
March 13, 2017

This is an update of the Splunk Reference App - PAS for Splunk Enterprise 6.5. It includes improvements to:
- Improvements for Splunk Enterprise 6.5
- Improved event generation
- Better refresh of custom visualizations

The most up-to-date version of the release notes is available at
https://github.com/splunk/splunk-ref-pas-code/blob/master/README.md

This reference app comes with an associated guidance on how to build Splunk apps - http://dev.splunk.com/goto/devguide.

Version 1.5.0
Sept. 21, 2015

This is an update of the Splunk Reference App - PAS to Splunk Enterprise 6.3. It includes new features and improvements, such as custom alerts, keycard tracking dashboard, usage telemetry and refactored Google Drive data provider with a smooth OAuth2 token workflow manifested through the UI.

The most up-to-date version of the release notes is available at
https://github.com/splunk/splunk-ref-pas-code/blob/master/README.md

This reference app comes with an associated guidance on how to build Splunk apps - http://dev.splunk.com/goto/devguide.

Version 1.0.1
March 16, 2015

The most up-to-date version of the release notes is available at
https://github.com/splunk/splunk-ref-pas-code/blob/master/README.md

This reference app comes with an associated guidance on how to build Splunk apps - http://dev.splunk.com/goto/devguide.

Version 1.00
Jan. 27, 2015

The most up-to-date version of the release notes is available at
https://github.com/splunk/splunk-ref-pas-code/blob/master/README.md

This reference app comes with an associated guidance on how to build Splunk apps.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.