<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk as a web application security tool in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-as-a-web-application-security-tool/m-p/527465#M11932</link>
    <description>&lt;P&gt;I am relatively new to Splunk as it is&lt;STRONG&gt; really&lt;/STRONG&gt; used.&lt;/P&gt;&lt;P&gt;My previous usage has all been ad hoc when it was made available to me for log analysis after an "event". That usage was mostly the equivalent of egrep + regular expressions.&amp;nbsp; Splunk and I got the job done.&lt;/P&gt;&lt;P&gt;I am finally in a place where all the features of Splunk are being ( or are intended to be ) used.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am being asked if Splunk can function as a web application security testing tool - ala BurpSuite or ZAP or Nikto or the like.&lt;/P&gt;&lt;P&gt;My take is no - that Splunk can perform analysis functions after the fact that can potentially reveal and alert on web application security issues - but it is not a substitute for dedicated tools of the sort previously mentioned.&lt;/P&gt;&lt;P&gt;Have I got this right?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 02 Nov 2020 01:03:41 GMT</pubDate>
    <dc:creator>logjam01</dc:creator>
    <dc:date>2020-11-02T01:03:41Z</dc:date>
    <item>
      <title>Splunk as a web application security tool</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-web-application-security-tool/m-p/527465#M11932</link>
      <description>&lt;P&gt;I am relatively new to Splunk as it is&lt;STRONG&gt; really&lt;/STRONG&gt; used.&lt;/P&gt;&lt;P&gt;My previous usage has all been ad hoc when it was made available to me for log analysis after an "event". That usage was mostly the equivalent of egrep + regular expressions.&amp;nbsp; Splunk and I got the job done.&lt;/P&gt;&lt;P&gt;I am finally in a place where all the features of Splunk are being ( or are intended to be ) used.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am being asked if Splunk can function as a web application security testing tool - ala BurpSuite or ZAP or Nikto or the like.&lt;/P&gt;&lt;P&gt;My take is no - that Splunk can perform analysis functions after the fact that can potentially reveal and alert on web application security issues - but it is not a substitute for dedicated tools of the sort previously mentioned.&lt;/P&gt;&lt;P&gt;Have I got this right?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 01:03:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-web-application-security-tool/m-p/527465#M11932</guid>
      <dc:creator>logjam01</dc:creator>
      <dc:date>2020-11-02T01:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk as a web application security tool</title>
      <link>https://community.splunk.com/t5/Security/Splunk-as-a-web-application-security-tool/m-p/527473#M11933</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/228319"&gt;@logjam01&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk isn't a scanner, Splunk is a log management and a correlation system system (in addition to an infinity of other things) so you can use it to tale the results of a scan and correlate them with its informations about different systems.&lt;/P&gt;&lt;P&gt;e.g.: Splunk Mission Control integrates Tenable.io to have the scan results in the same interface.&lt;/P&gt;&lt;P&gt;You should understand the features of Splunk to understand what to do with him and what to do integrating a different tool.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 07:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-as-a-web-application-security-tool/m-p/527473#M11933</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-11-02T07:14:35Z</dc:date>
    </item>
  </channel>
</rss>

