127 lines
7.5 KiB
Plaintext
127 lines
7.5 KiB
Plaintext
<div align="center">
|
|
<img width="344" height="193" src="https://raw.githubusercontent.com/sduff/awesome-splunk/master/splunk.jpg" alt="Splunk">
|
|
</div>
|
|
|
|
# Awesome Splunk [](https://awesome.re)
|
|
|
|
> A curated list of awesome apps, visualisations and other resources for Splunk.
|
|
|
|
[*Splunk*](https://splunk.com) captures, indexes, and correlates real-time data in a searchable
|
|
repository from which graphs, reports, alerts, dashboards, and visualizations
|
|
can be generated. It is widely used in industries such as finance, utilities,
|
|
healthcare and manufacturing for use-cases including security, compliance and
|
|
IT service monitoring.
|
|
|
|
## Contents
|
|
|
|
- [Basics](#basics) Basic resources for getting started
|
|
- [Apps](#apps)
|
|
- [Premium Apps](#premium-apps)
|
|
- [Visualisations](#visualisations)
|
|
- [Conferences, Meet-Ups and Socialising](#conferences-meet-ups-and-socialising)
|
|
- [Unofficial Resources](#unofficial-resources)
|
|
|
|
## Basics
|
|
|
|
Basic resources for getting started with Splunk.
|
|
|
|
- [Splunk Website](https://splunk.com) - Splunk's Homepage.
|
|
- [Downloads](https://www.splunk.com/download) - Download page.
|
|
- [Previous Releases](https://www.splunk.com/page/previous_releases) - Previous versions of Splunk Enterprise, Splunk Forwarders.
|
|
- [Splunk Answers](https://answers.splunk.com) - Splunk's Community Questions and Answers.
|
|
- [SplunkBase](https://splunkbase.splunk.com) - Splunk and Community built apps and add-ons.
|
|
- [Splunk Blogs](https://blogs.splunk.com/) - Blog posts on various topics.
|
|
- [Splunk Dev](https://dev.splunk.com) - Develop on Splunk.
|
|
- [Free Dev License](https://dev.splunk.com/enterprise/dev_license/) - Request a free Splunk Developer license.
|
|
- [Splunk Docs](https://docs.splunk.com/) - Documentation.
|
|
- Splunk Sizing Calculators
|
|
- [Storage](https://splunk-sizing.appspot.com/) - Web Based Storage Requirement Calculator.
|
|
|
|
## Apps
|
|
|
|
Recommended Splunk Apps.
|
|
|
|
- [Splunk App for Infrastructure](https://www.splunk.com/en_us/software/splunk-enterprise/server-and-infrastructure-monitoring-and-troubleshooting.html) - Correlate logs and metrics for infrastructure monitoring.
|
|
- [Splunkbase Entry](https://splunkbase.splunk.com/app/3975/) - Download page.
|
|
- [SAI Documentation](https://docs.splunk.com/Documentation/InfraApp) - Splunk App for Infrastructure Documentation.
|
|
- [SAI Install Guide](https://docs.splunk.com/Documentation/InfraApp/latest/Install/About)
|
|
- [Miscellaneous Scripts for fixing issues with the Universal Forwarder](https://github.com/jimmyatSplunk/SplunkForwarderRepairKit) - This kit was compiled based on common issues with Splunk deployments and managing idiosyncrasies that tend to naturally occur.
|
|
|
|
### Premium Apps
|
|
|
|
Premium Apps for Splunk.
|
|
|
|
#### Enterprise Security
|
|
|
|
Splunk Enterprise Security is the nerve centre of the security ecosystem, giving teams the insight to quickly detect and respond to internal and external attacks, simplify threat management minimizing risk.
|
|
|
|
- [ES Home Page](https://www.splunk.com/en_us/software/enterprise-security.html) - Splunk's Home Page for Enterprise Security.
|
|
- [ES Splunkbase Entry](https://splunkbase.splunk.com/app/263/) - Download page (if licensed).
|
|
- [ES Documentation](https://docs.splunk.com/Documentation/ES/latest) - Splunk documentation for Enterprise Security.
|
|
- [Awesome-ES](https://github.com/sduff/awesome-es/) - An Awesome list for all things Enterprise Security.
|
|
|
|
#### IT Service Intelligence
|
|
|
|
Splunk IT Service Intelligence (ITSI) is a monitoring and analytics solution powered by artificial intelligence for IT Operations (AIOps) that provides visibility into health and key performance indicators of critical IT and business services, and its infrastructure.
|
|
|
|
- [ITSI Home Page](https://www.splunk.com/en_us/software/it-service-intelligence.html) - Splunk's Home Page for IT Service Intelligence.
|
|
- [ITSI Splunkbase Entry](https://splunkbase.splunk.com/app/1841/) - Download page (if licensed).
|
|
- [ITSI Documentation](https://docs.splunk.com/Documentation/ITSI/latest) - ITSI Documentation.
|
|
- [Awesome-ITSI](https://github.com/sduff/awesome-itsi/) - An Awesome list for all things IT Service Intelligence.
|
|
|
|
## Visualisations
|
|
|
|
- [Event Timeline Viz](https://splunkbase.splunk.com/app/4370/) - Interactive timeline with call-outs for events.
|
|
- [Timeline](https://splunkbase.splunk.com/app/3120/) - Interactive timeline.
|
|
- [Halo](https://splunkbase.splunk.com/app/3514/) - Hierarchical, relational pie charts.
|
|
- [Heat Map](https://splunkbase.splunk.com/app/4460/) - A grid of related measurements, colour intensity derived from the value.
|
|
- [Calendar Heat Map](https://splunkbase.splunk.com/app/3162/) - Heatmap broken down by days.
|
|
- [Punchcard](https://splunkbase.splunk.com/app/3129/) - Punchcard Visualisation.
|
|
- [Horizon Chart](https://splunkbase.splunk.com/app/3117/) - Horizon Chart Visualisation.
|
|
- [Sankey Diagram](https://splunkbase.splunk.com/app/3112/) - Sankey Diagram Visualisation.
|
|
- [WebGL Globe](https://splunkbase.splunk.com/app/3674/) - Spinning globe with events correlated to locations (flashy C-level eye-candy).
|
|
- [Splunkbase Custom Visualizations](https://splunkbase.splunk.com/apps/#/app_content/visualizations) - Download other custom visualizations from Splunkbase.
|
|
|
|
## Conferences, Meet-Ups and Socialising
|
|
|
|
- [UserGroups](https://usergroups.splunk.com/) - Find a nearby usergroup.
|
|
- [.Conf](https://conf.splunk.com) - Splunk's annual conference website.
|
|
- [Past .Conf Material](https://conf.splunk.com/watch/conf-online.html) - Watch past presentations and download the slides from past .conf presentations.
|
|
- [Splunk UserGroups Slack](http://splk.it/slack) - Splunk's publicly accessible Slack.
|
|
- [/r/Splunk](https://reddit.com/r/splunk) - Unofficial Sub-Reddit.
|
|
- [IRC](https://wiki.splunk.com/Community:IRC) - Instructions for connecting to `#splunk` of Efnet.
|
|
- [Splunk Store](https://www.mylogocloud.com/splunk) - Order some Splunk Schwag you missed from a meetup or .conf.
|
|
- [Splunk Trust](https://www.splunk.com/en_us/community/splunk-trust.html) - The Splunk Trust is an invite only group of Splunk Ninjas.
|
|
|
|
## Unofficial Resources
|
|
|
|
Useful Splunk resources that are not specifically associated with Splunk Inc.
|
|
|
|
#### Personal Home Pages
|
|
|
|
- [Simon Duff](https://simonduff.net/splunk) - Miscellaneous scripts and visualisations.
|
|
- [Ryan Faircloth](https://www.rfaircloth.com/) - Security and Syslog related materials.
|
|
- [George Starcher](http://www.georgestarcher.com/) - Many Splunk related items, including details on Splunk ES's Extreme Search.
|
|
- [Anthony Tellez](https://anthonygtellez.github.io/) - Security and Machine Learning items.
|
|
- [Duane Waddle](https://www.duanewaddle.com/) - Miscellaneous Splunk items.
|
|
- [Vladimir's GitHub](https://github.com/hire-vladimir/) - Code for a number of Splunk resources, including [CIM Validation](https://github.com/hire-vladimir/SA-cim_vladiator).
|
|
- [Nico's GitHub](https://github.com/nicovdw/) - Repository of searches and dashboards to assist with optimising concurrency settings.
|
|
- [David Veuve](https://www.davidveuve.com/tech/) - Some early resources on Splunk basics and optimisations (infrequently updated).
|
|
|
|
#### SPL Repositories
|
|
|
|
Collections of useful Splunk searches
|
|
|
|
- [GoSplunk](https://gosplunk.com/) - Search Engine for Splunk Queries split by sourcetype and use-case.
|
|
|
|
## Contribute
|
|
|
|
Contributions welcome! Read the [contribution guidelines](contributing.md) first.
|
|
|
|
## Licence
|
|
|
|
[](https://creativecommons.org/publicdomain/zero/1.0)
|
|
|
|
To the extent possible under law, Simon Duff has waived all copyright and
|
|
related or neighbouring rights to this work.
|