Sandfly Agentless Security for Linux

Splunk Community

Sandfly Agentless Security for Linux

Sandfly Agentless Security for Linux
Sandfly is an agentless intrusion detection and incident response platform for Linux. Sandfly automatically analyzes Linux hosts for intruders 24 hours a day without loading any software on your endpoints. Additionally, Sandfly can retrieve hardware, operating system and related data for analysis in Splunk. Sandfly works across virtually all Linux distributions immediately without risk to stability or performance. The Sandfly Security App for Splunk includes dashboards, reports and logic for analyzing data ingested from a Sandfly server such as security alerts, suspicious activity and general software and hardware metrics. Data retrieved by Sandfly can also be used by Splunk users to build anomaly detection models, incident response and insights into software and hardware versions of your Linux fleet. This app requires that the Sandfly Security Add-on for Splunk (TA-sandfly-security) already be installed and configured to ingest data into your specified index and configured with the correct sourcetype (sandfly:alarms).
0 topics and 0 replies mentioned Sandfly Agentless Security for Linux in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.