<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I use Splunk for NERC baseline compliance? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-use-Splunk-for-NERC-baseline-compliance/m-p/468251#M74259</link>
    <description>&lt;P&gt;The Splunk Add-on for Unix and Linux collects all of these for you:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Sourcetypes"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Sourcetypes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But if you want to roll your own specifically to collect data with the flags you specify I would deploy them as scripted inputs (like TA-nix) and have Splunk run the job and index the data rather than an external Cron job.&lt;/P&gt;

&lt;P&gt;Take a look at the app and see if it works for you - long term it would be far simpler than managing your own, as all of the field extractions are provided for you.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/833"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2020 11:54:11 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2020-02-11T11:54:11Z</dc:date>
    <item>
      <title>How do I use Splunk for NERC baseline compliance?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-use-Splunk-for-NERC-baseline-compliance/m-p/468250#M74258</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;

&lt;P&gt;I am trying to leverage splunk for NERC Compliance, but more than just logging. I want to get baseline configuration which captures OS, Patches, Software, and Port and Services.&lt;/P&gt;

&lt;P&gt;My idea was to have the system generate the information and write it to a file and have the splunk universal forwarder monitor the file daily.&lt;/P&gt;

&lt;P&gt;There would be a cronjob that would run daily to execute the commands like:&lt;/P&gt;

&lt;P&gt;1) netstat -ano&lt;BR /&gt;
2) uname -r&lt;BR /&gt;
3) rpm -qa&lt;/P&gt;

&lt;P&gt;This would then get ingested into Splunk. How has the community been using Splunk for NERC Baseline compliance? Are there any add-ons that could help?&lt;/P&gt;

&lt;P&gt;It would need to be able to track changes to the baseline of allowable port and services, change records of the change, and run reports on a baseline of a particular day. This last part I was thinking of using a dash board or creating a table. &lt;/P&gt;

&lt;P&gt;Thoughts or suggestion? &lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 17:10:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-use-Splunk-for-NERC-baseline-compliance/m-p/468250#M74258</guid>
      <dc:creator>huangc</dc:creator>
      <dc:date>2020-02-06T17:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do I use Splunk for NERC baseline compliance?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-use-Splunk-for-NERC-baseline-compliance/m-p/468251#M74259</link>
      <description>&lt;P&gt;The Splunk Add-on for Unix and Linux collects all of these for you:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Sourcetypes"&gt;https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Sourcetypes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But if you want to roll your own specifically to collect data with the flags you specify I would deploy them as scripted inputs (like TA-nix) and have Splunk run the job and index the data rather than an external Cron job.&lt;/P&gt;

&lt;P&gt;Take a look at the app and see if it works for you - long term it would be far simpler than managing your own, as all of the field extractions are provided for you.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/833"&gt;https://splunkbase.splunk.com/app/833&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2020 11:54:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/How-do-I-use-Splunk-for-NERC-baseline-compliance/m-p/468251#M74259</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2020-02-11T11:54:11Z</dc:date>
    </item>
  </channel>
</rss>

