<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261205#M30104</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Is there a way with OSSEC to monitor when software is being installed?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2016 08:02:54 GMT</pubDate>
    <dc:creator>nickbijmoer</dc:creator>
    <dc:date>2016-12-02T08:02:54Z</dc:date>
    <item>
      <title>Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261205#M30104</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Is there a way with OSSEC to monitor when software is being installed?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 08:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261205#M30104</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-12-02T08:02:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261206#M30105</link>
      <description>&lt;P&gt;@nickbijmoer - Are you using the &lt;A href="https://splunkbase.splunk.com/app/2808/"&gt;Splunk Add-on for OSSEC&lt;/A&gt;? I just want to make sure your post is tagged correctly. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2016 23:55:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261206#M30105</guid>
      <dc:creator>aaraneta_splunk</dc:creator>
      <dc:date>2016-12-02T23:55:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261207#M30106</link>
      <description>&lt;P&gt;@aaraneta, Yes I use the splunk add-on for ossec. &lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 08:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261207#M30106</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-12-05T08:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261208#M30107</link>
      <description>&lt;P&gt;If you are looking to integrate w ES, the ossec_file_integrity_monitoring source type maps to change analysis and the ossec_alert maps to alert data model. &lt;/P&gt;

&lt;P&gt;You could adapt some of the existing correlation searches that use change analysis to fit this need or use the guided search to build a correlation search.  You will want to think about how often you want to be alerted to these changes and if there is a certain threshold you would want to set. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 11:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261208#M30107</guid>
      <dc:creator>jstoner_splunk</dc:creator>
      <dc:date>2020-09-29T11:58:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261209#M30108</link>
      <description>&lt;P&gt;Im trying to integrate it in Splunk enterprise, since we dont have enterprise security here, is it also possible on enterprise edition?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 08:46:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261209#M30108</guid>
      <dc:creator>nickbijmoer</dc:creator>
      <dc:date>2016-12-06T08:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for OSSEC: Is there a way with OSSEC to monitor when software is installed?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261210#M30109</link>
      <description>&lt;P&gt;Yes.  You can use the common information model and and the associated TA on splunkbase &lt;A href="https://splunkbase.splunk.com/app/2808/"&gt;https://splunkbase.splunk.com/app/2808/&lt;/A&gt; and build a datamodel search using the change analysis data model or you can just take the ossec data in and then build some searches based on what you see.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 15:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-OSSEC-Is-there-a-way-with-OSSEC-to-monitor/m-p/261210#M30109</guid>
      <dc:creator>jstoner_splunk</dc:creator>
      <dc:date>2016-12-06T15:00:39Z</dc:date>
    </item>
  </channel>
</rss>

