A Splunk technology add-on for osquery
| branch | build status |
|---|---|
| master |
- Original Author: Jose Hernandez
- Current maintainers:
- Sourcetype: osquery:results, osquery:snapshots, osquery:INFO, osquery:WARNING, osquery:ERROR
- Has index-time ops: false
- Parses and extracts fields for the following logs:
osqueryd.INFO, osqueryd.WARNING, osqueryd.ERRORosqueryd.results.logosqueryd.snapshots.log
- Provides Datamodel Mapping for:
- Alerts Data Model base on alerts from packs
- Changes Data Model base on FIM events from packs
- Endpoint Data Model base on Splunks Query Pack (todo)
- Does correct time extraction
- Remember to drop the TA in your indexers as well as your forwarders
- Do not forget to remove the example
default/inputs.conf - Add the Splunk query pack to your osquery agent (todo)
- Test Changes Data model mapping for FIM events in the results log
- Create a splunk query pack
- Populate Endpoint DM with the results of the splunk query pack