Skip to content

SigmaHQ/pySigma-backend-splunk

Folders and files

NameName
Last commit message
Last commit date

Latest commit

15218df Â· Jan 23, 2025
Nov 29, 2024
Jan 23, 2025
Jan 23, 2025
Jan 29, 2024
Apr 11, 2022
Jan 28, 2024
Feb 12, 2022
Mar 21, 2022
Apr 11, 2022
Jan 23, 2025
Dec 13, 2023
Jan 23, 2025

Repository files navigation

Tests Coverage Badge Status

pySigma Splunk Backend

This is the Splunk backend for pySigma. It provides the package sigma.backends.splunk with the SplunkBackend class. Further, it contains the following processing pipelines in sigma.pipelines.splunk:

  • splunk_windows_pipeline: Splunk Windows log support
  • splunk_windows_sysmon_acceleration_keywords: Adds fiels name keyword search terms to generated query to accelerate search.

It supports the following output formats:

  • default: plain Splunk queries
  • savedsearches: Splunk savedsearches.conf format.

This backend is currently maintained by: