Skip to main content

pySigma Splunk backend

Project description

Tests Coverage Badge Status

pySigma Splunk Backend

This is the Splunk backend for pySigma. It provides the package sigma.backends.splunk with the SplunkBackend class. Further, it contains the following processing pipelines in sigma.pipelines.splunk:

  • splunk_windows_pipeline: Splunk Windows log support
  • splunk_windows_sysmon_acceleration_keywords: Adds fiels name keyword search terms to generated query to accelerate search.

It supports the following output formats:

  • default: plain Splunk queries
  • savedsearches: Splunk savedsearches.conf format.

This backend is currently maintained by:

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

pysigma_backend_splunk-1.1.0.tar.gz (15.6 kB view details)

Uploaded Source

Built Distribution

pysigma_backend_splunk-1.1.0-py3-none-any.whl (16.6 kB view details)

Uploaded Python 3

File details

Details for the file pysigma_backend_splunk-1.1.0.tar.gz.

File metadata

File hashes

Hashes for pysigma_backend_splunk-1.1.0.tar.gz
Algorithm Hash digest
SHA256 82c979e2e1e153d69c186cdc7457987132b721ffd8e60a8696a5c84905b64f0d
MD5 9d53ab695c769bae4b2babfb6b8f8e71
BLAKE2b-256 12a6846bd98a94cb3230e072ad1598c43ca34da4dbc9979e47d3689a09f708f8

See more details on using hashes here.

File details

Details for the file pysigma_backend_splunk-1.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for pysigma_backend_splunk-1.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c681bae6480496604af1f230c2fd0d697cf187482730c5a07789d9141f81faa2
MD5 00defcc1ce03ed1107cd94dcee612198
BLAKE2b-256 4001217201109a076c65016162263fbe1701c89906b574ba5ade6364c5b87e2e

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page