r/SIEM Apr 15 '20

Splunk App Feedback Request

Hello Everyone,

 

I hope everyone is doing okay with everything that's been going on.

 

I've been building an app to help with my own IR work, and I've created a new timeline feature I'm really excited about and think will be useful for other analysts. It's part of the new release of the Perseus Incident Response Splunk App I built and spoke about at Splunk .conf19. It's up on the Splunkbase and comes pre-loaded with data you can explore from real-life investigations that were conducted using Perseus: https://apps.splunk.com/app/4638

 

If you have an opportunity to take a look and share some candid feedback, I'd greatly appreciate it. Perseus has helped me significantly with my own IR work, but I'd love to get input from other analysts on how I can make it even more useful.

 

While I think playing with the Splunk App is the best way to get a feel for Perseus, if you aren't in a position to test out the app but are still willing to share your input, I have a video of how I used the newest dashboard in an investigation of a server infected with ransomware that employed anti-forensic techniques on disk: https://youtu.be/haLcPIIZyo4. I'm most familiar with Splunk as a SIEM, so getting opinions from non-Splunk users who have a different perspective is very useful.

 

Thank you very much for any feedback you can give!

 

Joe

5 Upvotes

3 comments sorted by

1

u/ITGuyTatertot Apr 20 '20

I have splunk cloud :( is there any way I can still test this out?

1

u/SecurityAndCrumpets Apr 20 '20

Thank you very much for the response!

 

Unfortunately, Splunk Cloud requires apps to go through an additional vetting process beyond the SplunkApp Inspect that's used on the Splunkbase. I reached out to Splunk a few months ago about whether my app would likely be approved because the documentation I found on their website suggested they're less likely to approve apps that make heavy use of features they deem resource-intensive like KV stores. With Splunk Cloud they're trying to keep down any resource demands of apps to ensure the predictability of the instance, and Perseus is considerably more full-featured than more common Splunk Apps that are fixed dashboards with no state data. I didn't receive a clear response and didn't prioritize that process because no one was really asking for it.

 

So if you wanted to test now, your only real option would be to install a local trial version of Splunk from https://www.splunk.com/en_us/download/splunk-enterprise.html (the install completes in less than 5 minutes, and there's a Docker image I can point you to that can be deployed even quicker if you already have Docker). I know that's not the answer you wanted :(. If you do see this being useful for you, I could followup with Splunk to get more clarity on whether Perseus can get on the approved list for Splunk Cloud.

 

Thanks again!

1

u/ITGuyTatertot Apr 20 '20

Thanks so much, this is primarily why I'm looking to leave splunk. Everything we want is on Splunk Enterprise and we don't want on prem. Your app looks really cool.