Security

Splunk as a web application security tool

logjam01
Engager

I am relatively new to Splunk as it is really used.

My previous usage has all been ad hoc when it was made available to me for log analysis after an "event". That usage was mostly the equivalent of egrep + regular expressions.  Splunk and I got the job done.

I am finally in a place where all the features of Splunk are being ( or are intended to be ) used. 

I am being asked if Splunk can function as a web application security testing tool - ala BurpSuite or ZAP or Nikto or the like.

My take is no - that Splunk can perform analysis functions after the fact that can potentially reveal and alert on web application security issues - but it is not a substitute for dedicated tools of the sort previously mentioned.

Have I got this right?

Thanks!

 

 

Labels (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @logjam01,

Splunk isn't a scanner, Splunk is a log management and a correlation system system (in addition to an infinity of other things) so you can use it to tale the results of a scan and correlate them with its informations about different systems.

e.g.: Splunk Mission Control integrates Tenable.io to have the scan results in the same interface.

You should understand the features of Splunk to understand what to do with him and what to do integrating a different tool.

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @logjam01,

Splunk isn't a scanner, Splunk is a log management and a correlation system system (in addition to an infinity of other things) so you can use it to tale the results of a scan and correlate them with its informations about different systems.

e.g.: Splunk Mission Control integrates Tenable.io to have the scan results in the same interface.

You should understand the features of Splunk to understand what to do with him and what to do integrating a different tool.

Ciao.

Giuseppe

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...