Skip to content
#

splunk-universal-forwarder

Here are 16 public repositories matching this topic...

This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup a Suricata Port Mirrored Server

  • Updated Sep 5, 2020

A cloud-based SOC Detection Engineering & Threat Hunting Lab built using Splunk, Sysmon, Windows Event Logs, and GCP to simulate real-world attacks, monitor endpoint telemetry, create detections and alerts, perform incident investigation, and analyze attacker behavior using SIEM and threat hunting techniques.

  • Updated Jun 7, 2026

Improve this page

Add a description, image, and links to the splunk-universal-forwarder topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the splunk-universal-forwarder topic, visit your repo's landing page and select "manage topics."

Learn more