Security

Is there an SBOM released for splunk and splunk apps?

argo
Explorer

Is there an SBOM released for Splunk and ideally for all the apps and add ons in splunkbase? We are looking to create an SBOM where splunk is part of our solution and as a result need an SBOM for splunk itself. Any pointers are appreciated. 

https://www.splunk.com/en_us/blog/learn/sbom-software-bill-of-materials.html

Labels (1)
Tags (1)
0 Karma
1 Solution

jeffbennett_spl
Splunk Employee
Splunk Employee

I don't know the name of the app yet, but searching splunkbase for SBOM will find it for you when it becomes available.

In regard to understanding what apps, add-ons, etc and their version numbers, you can run the search below. I recommend saving this search as a report and running it once a month. 

| rest splunk_server=local /services/apps/local | table title version | rename title as Title, version as Version

 

View solution in original post

jeffbennett_spl
Splunk Employee
Splunk Employee

There is an app being developed for this use case. It will provide SBOM info on Splunk and the software sources that go into Splunk. It should be available around mid or late September 2023 on Splunkbase. 

0 Karma

argo
Explorer

Oh that would be amazing. What would also be amazing is if it also can scan what apps you have loaded and report on those version numbers, etc. Do you know the name of the app yet to keep an eye out for it, or presumably searching for 'SBOM' will get me there when the time comes.

0 Karma

jeffbennett_spl
Splunk Employee
Splunk Employee

I don't know the name of the app yet, but searching splunkbase for SBOM will find it for you when it becomes available.

In regard to understanding what apps, add-ons, etc and their version numbers, you can run the search below. I recommend saving this search as a report and running it once a month. 

| rest splunk_server=local /services/apps/local | table title version | rename title as Title, version as Version

 

PickleRick
SplunkTrust
SplunkTrust

While I can't give you a definite answer on Splunk itself (that's something I'd ask the support about), there is no possibility of such thing for "all apps and addons in splunkbase" since it's highly dynamic, and the apps are being created and updated on almost daily basis so no such static list could exist especially that the apps are created by people and teams from all over the world independently.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Take Action Automatically on Splunk Alerts with Red Hat Ansible Automation Platform

 Are you ready to revolutionize your IT operations? As digital transformation accelerates, the demand for ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...