An open-source framework for building secure, reliable, and efficient SIEM integrations.
-
Updated
Mar 29, 2026 - Python
An open-source framework for building secure, reliable, and efficient SIEM integrations.
Automated threat intelligence collector built with Python and GitHub Actions — fetches recent IOCs from open sources, normalizes and enriches them (IP, URL, hash, CVE), and publishes ready-to-use feeds in CSV, JSON, and STIX formats.
🤖 Generate accurate Splunk SPL queries from natural language using AI, validated against live data for effective security analytics.
📊 Visualize Ubuntu journal logs with ease, enabling quick analysis of log activity and burst detection through a user-friendly Streamlit interface.
Full Splunk App for Bitsight Security Ratings. Monitor and visualize security ratings, portfolio companies, alerts, findings, exposed credentials, users, and threat intelligence from the Bitsight API.
SpeakQuery is an open-source, self-hosted search and ingestion engine that runs a custom query language over local Parquet and SQLite data, powering a Flask web UI plus cron-scheduled jobs for repeatable analytics and alerts.
Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.
Splunk Security Content
Parse a list of indicators into a dictionary or JSON structure for programmatic use.
Python automation suite and Splunk dashboard library for ADFS/Duo authentication security monitoring. 11 production dashboards, session auth workaround for restricted reverse proxies, OS keychain credential management.
Documenting my projects and experience as a Security Operations Analyst. For educational purposes only.
Ansible role for deploying and configuring Splunk Enterprise - includes HEC input, indexes, apps, and multi-disk storage with Doppler secrets integration
SDK for Developing Solutions in Splunk Enterprise with Python
Code repository for Cisco Live Session BRKGRN-1022
Censys Splunk Add-on and Apps
Enterprise-grade ICT infrastructure monitoring and security operations platform with Splunk. Demonstrates threat detection, Kenya Data Protection Act 2019 compliance, and 80% false positive reduction through alert tuning.
Add a description, image, and links to the splunk topic page so that developers can more easily learn about it.
To associate your repository with the splunk topic, visit your repo's landing page and select "manage topics."