splunk developer site

create Splunk App

Splunkbase

Splunk app & add-on

Splunk AppInspect

Splunk Develop

跟 syslog 相關的

pack Splunk App uisng Packing Toolkit

App Design Patterns

Splunk Syntax Highlight

可以在進階看有關 Splunk App 的部分

Restart Splunk Enterprise & refresh Splunk Web UI 的方式

  • Restart Splunk Enterprise:
    1. In Splunk Web, click Settings, then Server Controls, then Restart Splunk.
    2. When you log back in, navigate to your app. The navigation will be updated and your dashboard will be open by default.
  • Force a refresh of Splunk Web UI:
    • Navigate to http://localhost:8000/en-US/_bump, click Bump version to flush the client cache. If you make changes to client-side JavaScript, CSS, or static resources, this command forces those assets to be updated.
    • Navigate to http://localhost:8000/en-US/debug/refresh, click Refresh to refresh almost all Splunk Enterprise knowledge objects. To refresh only views, navigation, or saved searches, you could append ?entity=data/ui/views, ?entity=data/ui/nav, or ?entity=saved/searches to the end of the URL.
  • Understand asset caching and state changes in Splunk Enterprise

有關 splunk conf

Run using docker

parsing CEF format

Call to external Restful API

Document

相關的 conference

自動產生 event 的程式

可參考的 app install & 設定文件

刪除 index data 的方式

Reference Term

  • SIEM(Security Information Event Management)資安事件管理平台解決方案

Comments

2020-12-09