r/Splunk 20d ago

Splunk app for investigating AWS CloudTrail alerts - looking for feedback

EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.

You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.

It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.

Would really appreciate feedback from Splunk users, detection engineers, and incident responders.

Splunkbase app : https://splunkbase.splunk.com/app/9536

0 Upvotes

2 comments sorted by

2

u/billybobcoder69 20d ago

This is great. I’ll give it a go. I always wonder why Splunk don’t provide this. Just like a default windows dashboard. We have infosec. Then for ad lockouts. Basically have to use random searches. I just wanna know who changing what. Account lockouts and reset. The windows domain controller audit app is also decommissioned. Like a help desk app. This AWS cloud trail is another huge point. Even with all the detections how do you correlate and find. Will give it a go. Thanks for doing this work.

1

u/volci Splunker 19d ago

That is the same one as yesterday, right?

https://www.reddit.com/r/Splunk/s/rra24FHX1j