Refine your search:

0 ratings

Thanks For Downloading!

Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows:

Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into %PROGRAMFILES%\Splunk\etc\apps. Then restart Splunk using the splunk restart command or the GUI.

Unix/Linux: Decompress the downloaded file using a tool like tar -xvf and place the resulting folder into $SPLUNK_HOME/etc/apps. Then restart Splunk using the splunk restart command or the GUI.

Description

Centrify Insight is a Splunk application that listens to Active Directory domain controllers and security event logs, as well as *NIX syslog and Centrify Suite logs to provide the type of insight you need to answer security and forensic questions about Centrify secured systems.

Centrify Insight is also a great application for monitoring, searching and reporting on NIX login activity. Find you most active users, watch for failed login attempts and break out login attempts by login method (ssh, console, su) and user type (active directory domain user, local user, root).
NOTE: In order for the Centrify Insight application to monitor
NIX login activities, you must use both the splunk universal forwarder and the Centrify Insight *NIX Collector application (<http://splunk-base.splunk.com/apps/31874/centrify-insight-nix-collector>).

Versions and Release Notes

Version 1.4.0 (current version - updated Jan 14, 2013)
release notes:

Centrify Insight 1.4 adds new views, features and fixes. Here is a list of highlighted new features:
1. Support DirectAuthorize for *NIX – able to monitor role assignments, roles, rights, etc.
2. Compatible with Suite 2013 (DirectControl/DirectAuthorize 5.1)
3. We now use separate indexes for Centrify data inputs to improve performance
4. Support Splunk WMI configuration
5. Support for latest Splunk version 5.0.1

show older versions »
Version 1.3.0 (updated Jul 18, 2012)
release notes:

NEW! Support for Centrify 5.x Zones, Zone hierarchy, Zone users, Zone groups, Zoned computers, Computer roles.

Enhanced AD and Zone activity views

Support for Splunk 4.3.x

Enhanced documentation

Version 1.0.0 (updated Jul 18, 2012)
Version 1.2.0 (updated Jan 30, 2012)
release notes:

Centrify Insight 1.2 is a stability and feature release that enhances the *NIX login activity dashboards, adds a system access summary dashboard and adds summaries of successful/failed login attempts, breaks them down by login type (SSH, Telnet, su, console) and adds monitoring of password changes initiated from *NIX systems for either local or AD users. More details:

New easier to use navigation menus and home dashboard.
New or updated dashboards for:
- System access
- *NIX user login
- Centrify data in Active Directory
- Centrify agent health
- Centrify logs and config files
New views for:
- user accounts and groups
- who is logged on to systems and their last logon
- password changes to AD or local accounts
- AD computer account changes
- Centrify agent uptime and heartbeat

Version 1.1.0 (updated Oct 05, 2011)
release notes:

Centrify Insight 1.1 is a major release that adds *NIX login activity dashboards, custom searches and reports to the existing custom searches for Active Directory user/group/computer activity and Centrify Zone activity.

Version 1.0.1 (updated Jun 01, 2011)
release notes:

Fixes to allow for Centrify data in Active Directory in a non-default OU.

posted 02 May '11, 23:29

Corey's gravatar image

Corey
47817
accept rate: 0%

new version 14 Jan, 11:11


2 Reviews
2 reviews, 0 ratings, average 0.00

Did you find this app useful?

Hi,

yesterday i installed the requiered packages to integrate Centrify into a fresh installed splunk 5.0.1.

Everytime i want to view details from an entry in one of the dashboards i get the following:

"splunk encountered the following unknown module: SearchMode The view may not load properly"

Any solution for that. Google doesn't give a result about "SearchMode"?

Best regards

Thomas

comments (0)

reviewed 20 Dec '12, 00:51

ductom2002's gravatar image

ductom2002
111
accept rate: 0%

edited 20 Dec '12, 01:49

Reviews related to version 1.0.0 (current is 1.4.0)

Can I suggest an index name change.. "os" doesn't make sense. How about "Centrify" or "CentrifyInsight" for the index?

comments (0)

reviewed 14 Mar '12, 16:50

JasonCzerak's gravatar image

JasonCzerak
31
accept rate: 0%

Price: Free
Author: Corey
Version: 1.4.0
Splunk compatibility: 5.x, 4.3, 4.2
Updated:
License: Centrify Express Use License

This app is not covered by any support agreements in place with Splunk. If you have questions about the installation or operation of this app, please contact the author.

Follow this app

Log In to enable email subscriptions

RSS:

Reviews

Reviews + Comments

Ask a Question
Copyright © 2005-2012 Splunk Inc. All rights reserved.