Thanks For Downloading!Review the documentation below and follow any custom installation steps. If no install steps are listed, most Splunk Apps and Add-ons can be installed as follows: Windows: Decompress the downloaded file using a tool like 7-Zip and place the resulting folder into Unix/Linux: Decompress the downloaded file using a tool like DescriptionThe FISMA app is a compliance auditing solution for NIST 800-53 guidelines. Splunk for FISMAVersion: 1.1.2 Developed by: Mike Wilson (mwilson at splunk.com) GeneralThe FISMA app is a set of searches and views which can be used to audit NIST 800-53 compliance. This app does not provide data inputs, extractions, or tags itself. This app is a "framework" which is dependent on the Common Information Model eventtyping and tagging being provided by external add-ons. The app can be utilized to integrate any relevant data sources if the CIM fields and tagging match. Each control has it's own Help link which describes the required tags and fields for the view. Technology Add-ons such as the Splunk for Windows technology add-on and the Splunk for Unix and Linux technology add-on are examples of two such supporting add-ons which should be used in conjunction with the FISMA app. Please contact fed@splunk.com if you require additional Technology Add-ons which are not available on Splunkbase. InstallationThe app should be installed on your search head. Summary indexes will be created, and so you may either install the app on indexers or deploy the indexes.conf alone. Additional Technology Add-ons (i.e. CIM mapping, whether downloaded from splunkbase or hand built) are required for this app to work properly. The installation of TAs will be specific to the TA itself and its documentation should be reviewed separately. The FISMA app performs summary indexing on data, and views will revert to looking at summary indexed data if a time period of 6 hours or greater is selected from the view's time picker. Additionally, the Overview page uses summary indexed data. Because of this, you should not expect to see all charts populate immediately after installation. There is a nix-based backfill script in the app's bin directory. Controls11 Control Families
Example Data Sources
ConnectionsInternal: External: Known IssuesNone. CreditsDan Goldburt and team for the initial version of this app. Versions and Release Notes
Version 1.1.2 (current version - updated Apr 06, 2012)
|
The version prior to October 11th was also 1.1.2. Are there any changes in today's update?
Sorry, no new release here. I think there were some changes regarding splunkbase itself that triggered the change of date unfortunately.