Monitoring Splunk

Splunk & Ossec intergration

monitor
New Member

Splunk seems like an all around tool.

What is the advantage of incorporating the Ossec system into or with Splunk?

0 Karma

jhuebner
Explorer

The reporting and searching is much easier using SPLUNK to look at & do searches on the OSSEC data. The newest version of SPLUNK and the OSSEC plugin give you a whole new set of features.

I've not updated to the 2.5.1 version, I'm still on 2.4, but I think I'll give it a try, x.x.1 just came out.

0 Karma

esweeney
Splunk Employee
Splunk Employee

Users incorporate OSSEC alerts into Splunk to eliminate the need for a dedicated OSSEC web interface and allow for simplified incident analysis through aggregation and correlation.

Check out the app on Splunkbase: http://www.splunkbase.com/apps/All/4.x/app:Splunk+for+OSSEC+-+Splunk+v4+version

And an older blog detailing the value one company finds: http://www.ossec.net/main/splunk-ossec-integration

rayfoo
Path Finder

One that i can think of is that you can summarize data, or customize reports from Splunk, using OSSEC as an input.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...