Snort 3 JSON Alerts

Splunk Community

Snort 3 JSON Alerts

Snort 3 JSON Alerts
This repository is a Technology Add-On for Splunk that allows you to ingest IDS alerts into Splunk from Snort 3 in json format. This plugin normalizes these alerts conform to the 'Intrusion Detection' model in the Splunk Common Information Model (CIM), and can be accessed within any app or dashboard that reports Intrusion Detection events.
0 topics and 0 replies mentioned Snort 3 JSON Alerts in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.