RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high-fidelity, low-volume alerts.
☆67Jun 2, 2026Updated last month
Alternatives and similar repositories for rba
Users that are interested in rba are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Splunk spec files version history☆46Jul 10, 2026Updated last week
- scripts using splunk application lookup-editor endpoint. Download, upload and update splunk lookups content☆32Jul 1, 2024Updated 2 years ago
- Data validator agains Splunk Common Information Model (CIM)☆80Jun 21, 2026Updated 3 weeks ago
- Linux version of Splunk MCP LLM MCP SIEMulator . A Docker lab integrating Splunk SIEM with Ollama LLM via Model Context Protocol for AI-p…☆18Jun 20, 2026Updated last month
- Splunk Content Control Tool☆134May 6, 2026Updated 2 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Grand Central logging for Cloud Services to Splunk☆37Jan 22, 2022Updated 4 years ago
- Splunk connect for SNMP☆41Updated this week
- Monitor syslog collection infrastructure & offer syslog configuration templates.☆27Feb 9, 2018Updated 8 years ago
- Config viewer and file editor for Splunk. Based on VSCode.☆35Jun 14, 2026Updated last month
- Splunk app to monitor the /etc directory of Splunk for all changes of .conf files☆13Jan 26, 2018Updated 8 years ago
- Splunk Connect for Syslog☆180Updated this week
- Bulk modify Splunk Knowledge Object's owners, permissions, apps, sharing and move them to another app☆26Aug 27, 2022Updated 3 years ago
- Azure Functions for getting data in to Splunk☆33Jul 13, 2026Updated last week
- Admin Config Service CLI☆17Jun 29, 2026Updated 3 weeks ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Sysmon Splunk App☆47Aug 21, 2018Updated 7 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆69Jul 2, 2026Updated 2 weeks ago
- Splunk Admins application to assist with troubleshooting Splunk enterprise installations☆101Updated this week
- Atlasian JIRA add-on for Splunk alert actions☆15May 6, 2026Updated 2 months ago
- Splunk Security Content☆1,654Updated this week
- ☆76Jul 15, 2021Updated 5 years ago
- A repository of curated datasets from various attacks☆790Updated this week
- Workshop showing you how to setup Amazon Web Services to send data to Splunk☆74Sep 9, 2020Updated 5 years ago
- Splunk Operator for Kubernetes☆259Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- CrowdStrike Falcon log forwarder from falcon S3 bucket to your S3 bucket☆10Apr 15, 2021Updated 5 years ago
- Shell script to download apps from Splunkbase☆24May 19, 2020Updated 6 years ago
- Postfix Add-on for Splunk (Compliant with the Mail CIM model)☆11Mar 18, 2021Updated 5 years ago
- Ansible framework providing a fast and simple way to spin up complex Splunk environments.☆135Jun 19, 2026Updated last month
- Phantom Apps Repo☆82Nov 9, 2021Updated 4 years ago
- Risk Based Alerting Supporting Add-On (SA) for Splunk☆44Oct 28, 2021Updated 4 years ago
- backup app for Splunk and Terraform for recovery☆14Updated this week
- Splunk csv to KVStore ES Threat Intel☆11Jul 11, 2016Updated 10 years ago
- How to run cluster of Splunk Enterprise in Docker. Examples.☆34Oct 27, 2016Updated 9 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- MITRE ATT&CK Framework compliance dashboard and correlation searches that works with Splunk Enterprise Security and ES Content Update☆32Jun 2, 2026Updated last month
- scripts to configure the Splunk Universal Forwarder in a locked down state☆40Dec 13, 2018Updated 7 years ago
- MISP to Splunk Enterprise Security Theat Intelligence Framework Integration☆14Jul 11, 2023Updated 3 years ago
- Splunk App for Data Science and Deep Learning - container images repository☆64Jul 1, 2026Updated 2 weeks ago
- Maps+ for Splunk☆23Jun 30, 2026Updated 3 weeks ago
- Searches and dashboards to assist with optimising concurrency settings☆31Mar 4, 2022Updated 4 years ago
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆26Jun 28, 2026Updated 3 weeks ago