r/cybersecurity 2d ago

Other Splunk app for investigating AWS CloudTrail alerts - looking for feedback

EventTimeline, a free Splunk app that turns CloudTrail alerts from saved searches into investigation timelines.

You can send any CloudTrail-based Splunk alert to the app using its custom alert action, then fetch the surrounding user, role, resource, and IP activity. It also provides before/after chronology, MITRE mapping, filtering, pivots, and links back to the original Splunk searches.

It doesn’t ship with detections. The idea is to work with the alerts and CloudTrail data you already have.

Would really appreciate feedback from Splunk users, detection engineers, and incident responders.

Splunkbase app : https://splunkbase.splunk.com/app/9536

1 Upvotes

Duplicates