<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk &amp; Ossec intergration in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12726#M67</link>
    <description>&lt;P&gt;Users incorporate OSSEC alerts into Splunk to eliminate the need for a dedicated OSSEC web interface and allow for simplified incident analysis through aggregation and correlation.&lt;/P&gt;

&lt;P&gt;Check out the app on Splunkbase:
&lt;A href="http://www.splunkbase.com/apps/All/4.x/app:Splunk+for+OSSEC+-+Splunk+v4+version" rel="nofollow"&gt;http://www.splunkbase.com/apps/All/4.x/app:Splunk+for+OSSEC+-+Splunk+v4+version&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And an older blog detailing the value one company finds:
&lt;A href="http://www.ossec.net/main/splunk-ossec-integration" rel="nofollow"&gt;http://www.ossec.net/main/splunk-ossec-integration&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Sep 2010 05:26:28 GMT</pubDate>
    <dc:creator>esweeney</dc:creator>
    <dc:date>2010-09-09T05:26:28Z</dc:date>
    <item>
      <title>Splunk &amp; Ossec intergration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12724#M65</link>
      <description>&lt;P&gt;Splunk seems like an all around tool. &lt;/P&gt;

&lt;P&gt;What is the advantage of incorporating the Ossec system into or with Splunk?&lt;/P&gt;</description>
      <pubDate>Sat, 01 May 2010 02:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12724#M65</guid>
      <dc:creator>monitor</dc:creator>
      <dc:date>2010-05-01T02:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk &amp; Ossec intergration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12725#M66</link>
      <description>&lt;P&gt;One that i can think of is that you can summarize data, or customize reports from Splunk, using OSSEC as an input.&lt;/P&gt;</description>
      <pubDate>Wed, 05 May 2010 19:10:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12725#M66</guid>
      <dc:creator>rayfoo</dc:creator>
      <dc:date>2010-05-05T19:10:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk &amp; Ossec intergration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12726#M67</link>
      <description>&lt;P&gt;Users incorporate OSSEC alerts into Splunk to eliminate the need for a dedicated OSSEC web interface and allow for simplified incident analysis through aggregation and correlation.&lt;/P&gt;

&lt;P&gt;Check out the app on Splunkbase:
&lt;A href="http://www.splunkbase.com/apps/All/4.x/app:Splunk+for+OSSEC+-+Splunk+v4+version" rel="nofollow"&gt;http://www.splunkbase.com/apps/All/4.x/app:Splunk+for+OSSEC+-+Splunk+v4+version&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;And an older blog detailing the value one company finds:
&lt;A href="http://www.ossec.net/main/splunk-ossec-integration" rel="nofollow"&gt;http://www.ossec.net/main/splunk-ossec-integration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Sep 2010 05:26:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12726#M67</guid>
      <dc:creator>esweeney</dc:creator>
      <dc:date>2010-09-09T05:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk &amp; Ossec intergration</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12727#M68</link>
      <description>&lt;P&gt;The reporting and searching is much easier using SPLUNK to look at &amp;amp; do searches on the OSSEC data.  The newest version of SPLUNK and the OSSEC plugin give you a whole new set of features.&lt;/P&gt;

&lt;P&gt;I've not updated to the 2.5.1 version, I'm still on 2.4, but I think I'll give it a try, x.x.1 just came out.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2010 00:51:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-Ossec-intergration/m-p/12727#M68</guid>
      <dc:creator>jhuebner</dc:creator>
      <dc:date>2010-10-21T00:51:39Z</dc:date>
    </item>
  </channel>
</rss>

