Thinkst Canary Audit Input

Splunk Community

Thinkst Canary Audit Input

Thinkst Canary Audit Input
Pulls down Thinkst Canary audit logs using the API. Install on Splunk Cloud IDM or a heavy forwarder. Can also be installed on Search heads for the sourcetypes, but its clearer if you just create the sourcetype canarytools:audit manually with KV_MODE = none. Icon from https://www.vecteezy.com/vector-art/1919479-linear-audit-document-icons-design-isolated-on-white-background https://github.com/Bre77/TA_thinkst_canary_audit
0 topics and 0 replies mentioned Thinkst Canary Audit Input in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.