Ready Security Blocks for Splunk Environments
Browse our collection of modular security building blocks
VMware AVI Load Balancer & WAF - logging audit events source
- Parsing audit events of AVI
- CIM-compliant normalization for data model–based detections
- Documentation, appliance settings to enable auditing events reporting, tuning guidance if needed
Use case: Surprisingly, these events are often not collected by default.
Yet they are essential for understanding and auditing a critical part of your security architecture.
RedHat SSO – Authentication & Audit Pack
- Internal authentication and audit log parsing
- CIM-compliant normalization for data model–based detections
- 5 Detection rules for authentication misuse and anomalies
- Documentation, appliance settings to enable auditing events reporting, tuning guidance if needed
Use case: Surprisingly, these events are often not collected by default.
Yet they are essential for understanding and auditing a critical part of your security architecture.
All security blocks are designed by certified Splunk and security professionals and validated in production environments.