Skip to content

gmellini/minemeld-analysis

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

8 Commits
 
 
 
 
 
 

Repository files navigation

minemeld-analysis

Splunk application to check MineMeld logs sent via logstash connector

Splunk/MineMeld configuration is described in this post http://wp.me/p6LD4A-9f

Here a video of the app in action https://youtu.be/WJogETMlpcc

In order to have a working environment you need a custom TA (TA-custom-minemeld-ioc) to parse MineMeld JSON events https://github.com/gmellini/TA-custom-minemeld_ioc

The application check MineMeld events on index minemeld_ioc. If you want to change index name you have to adjust TA-custom-minemeld-ioc TA.

IMPORTANT Install the app in the Splunk Search Head (distributed environment) or Splunk single-istance

About

Splunk application to check MineMeld logs - see http://wp.me/p6LD4A-9f

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors