THOR APT Scanner v2

Splunk Community

THOR APT Scanner v2

THOR APT Scanner v2
This Splunk App helps to manage the log data transmitted by THOR and facilitates the analysis. Key Features of this App - Dashboard: Number of scans, scanned hosts, license usage, scans with different THOR/SPARK versions - Overview: Alert types over time, alert types by system, scan status by system, connection endpoints (geo location) - Universal View: Main THOR log analysis view with filters and sorting to process all log messages in an optimal way - Input: SYSLOG or TEXT (.txt) logs Requirements: THOR Add-on v2 https://splunkbase.splunk.com/app/3718/ Steps to get data into the Splunk App: - Use sourcetype='thor' for all your inputs (files/udp/tcp) Recommendation: - Create an index named 'thor' and make sure that the current user rule searches this index by default
0 topics and 0 replies mentioned THOR APT Scanner v2 in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.