The Community of Splunk Enthusiast

This is a fan site and not an official Splunk site

Menu
  • Home
  • BSides Splunk
    • Current Schedule
    • Current Talks
    • Archives
  • Call For Papers
    • Presentation Recording Tips

Oversight: Building an Asset Inventory Data Pipeline

Description:
Oversight is an add-on for compiling a comprehensive asset inventory, based on the data you already have in Splunk. Users enter data input parameters to define each data source, along with parameters to enrich, normalize, filter, and expire records.

Oversight dynamically builds knowledge objects, and uses custom alert actions to aggregate data, and handle record expiration. Oversight correlates records for assets with multiple IPs as well.

Speaker:
Phil Meyerson

Day and Time:
 

  • Home
  • BSides Splunk
    • Current Schedule
    • Current Talks
    • Archives
  • Call For Papers
    • Presentation Recording Tips

© 2020 Splunk Community. All Rights Reserved.