icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.
Log4Shell Vulnerability: Information and guidance for you. Get resources.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Hurricane Labs App for Shodan
SHA256 checksum (hurricane-labs-app-for-shodan_223.tgz) b9c8f0610b038648c2a473f06e1a52e241cf18ff522cca0ca5970a7ed556640e SHA256 checksum (hurricane-labs-app-for-shodan_222.tgz) c6d4c7378230088538ec4ab24cb7f1913118a134e814eb2f288d06fe03afdb9f SHA256 checksum (hurricane-labs-app-for-shodan_210.tgz) 6b3c3a744acded8978c990d0dcbc5a40c28e1098111a82bd57a1259d3aaf70d5 SHA256 checksum (hurricane-labs-app-for-shodan_209.tgz) dfacb7f208d4a5a294ededa0aaff1c7fb73ef0f5cdb050ca31fe463c51ef0c58 SHA256 checksum (hurricane-labs-app-for-shodan_208.tgz) d814de86a35515236a3824f0b65f07d278ec05ffa85bccfa49413445520867fc SHA256 checksum (hurricane-labs-app-for-shodan_207.tgz) 1c935b7ddcc861d29b85c1427eb9d273078fb0f786ee97986574ce5ece96b3de SHA256 checksum (hurricane-labs-app-for-shodan_206.tgz) 4a44975f70a67f78f4ee1f2f4ef6504fbac4bc99cb62197f1a8ab30eaf4247d2 SHA256 checksum (hurricane-labs-app-for-shodan_205.tgz) 061dc5a1ebb27f8abaf2c602788f445f39cb692fe6d504a9a02bec2548a1b57f SHA256 checksum (hurricane-labs-app-for-shodan_204.tgz) 4ab356c13990dc2b2941e7aa2489391a62aa24095efe96227af5bbe5314bf581 SHA256 checksum (hurricane-labs-app-for-shodan_203.tgz) 9cdc9f26af07b7ba5bb19a5d438fe1b5941f38c772dcf97e6013cbcc25ba5923 SHA256 checksum (hurricane-labs-app-for-shodan_202.tgz) 9129ca2b7bb85d9bf08111be82bce3d377094e190afa6bff38767088cd7f8b4b SHA256 checksum (hurricane-labs-app-for-shodan_201.tgz) 426cc6b1216cbd0990220c19413f37b9cc94e33125bedf72cad60da03ecca724 SHA256 checksum (hurricane-labs-app-for-shodan_151.tgz) f0c0985a2fd1bf634e0a15cac896207b5ddb451220933f6d8b49a0dc850ed9f0 SHA256 checksum (hurricane-labs-app-for-shodan_15.tgz) a7a64f443990b65e1f7fd2f3e869203679590dcb97ba9b091a55ec01a34ecfe2 SHA256 checksum (hurricane-labs-app-for-shodan_14.tgz) c682a8201488497886eac6aa0380268cec3a34bc7e89ad5b71796c3e40c87ee8 SHA256 checksum (hurricane-labs-app-for-shodan_12.tgz) 6a8ead46b73132b9993f9f6501415145de96bc3003180499b3478d0bc0137285 SHA256 checksum (hurricane-labs-app-for-shodan_11.tgz) 96bdd3ca3cf63846fff786cbe5d20f952a837f8156094b470f2b02539ca0ce6a SHA256 checksum (hurricane-labs-app-for-shodan_10.tgz) 948b72a896a8b8f87398c339e830f81d336881877c170ef90af6648e7fdea56e
To install your download
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate


Hurricane Labs App for Shodan

Splunk Cloud
This app is NOT supported by Splunk. Please read about what that means for you here.

Due to an expiring root certificate in the CA bundle that ships with Splunk 7.3 and older, this app won't be able to connect to Shodan if not installed on Splunk 8. To fix this, please install our "CA Cert Manager" app and follow the "Fixing expiring Sectigo certificates on older versions of Splunk" section of the README.


This app now includes what was in the SA-Shodan (https://splunkbase.splunk.com/app/1766/) app, which is now deprecated. It allows you to enter your external subnets and get an idea of what the Internet sees when it looks at your network (okay what bad guys can see) externally. It utilized the Shodan (www.shodanhq.com) so you will need an API key

Install App
Add API key
Restart Splunk
Enter Subnets in config screen
Either run the saved search manually or wait for it to run on schedule (every 12 hours by default)


Please send support inquiries to splunk-app@hurricanelabs.com.

Release Notes

Version 2.2.3
Jan. 4, 2022

Changed getshodan command to "events" type GeneratingCommand to avoid distribution to indexers. Thanks to Christoph Wiederkehr for this suggestion.

Version 2.2.2
Sept. 17, 2021
  • Case sensitivity fix on setup page
Version 2.1.0
May 21, 2021
Version 2.0.9
March 9, 2021

Fixed bug related to Shodan API returning a "_id" field in output. Added proxy support in shodan.conf (no GUI support currently, sorry).

Version 2.0.8
Dec. 18, 2019

Version 2.0.8 fixes a bug where additional pages of results weren't pulled properly.

Version 2.0.7
Oct. 28, 2019
Version 2.0.6
Oct. 3, 2019

Updates for v 2.0.6

  • Added ssl field to KV Store
  • Added note to README under Modifying limits.conf on how to accommodate longer field byte lengths.
Version 2.0.5
Sept. 23, 2019

Updates for v 2.0.5

  • Fixed out of range error when not using net: prefix.
Version 2.0.4
Sept. 18, 2019

Updates for v 2.0.4

  • Fixed typo on configuration page
Version 2.0.3
Sept. 12, 2019

Updates for v 2.0.3

  • Added time.sleep(1) to help with API timeout issues. Will still occur with large data-sets. See new debugging section in README.
  • Modified message on configuration page to make it clearer which KV store is not populating.
  • Added General Debugging section to README
  • Moved splunklib from lib into bin/lib
Version 2.0.2
Sept. 6, 2019

Updates for v 2.0.2:

  • Splunklib has been moved to lib directory to allow for Splunk Cloud installs
  • Lingering console.logs() in JavaScript have been removed
Version 2.0.1
May 15, 2019


The SA-Shodan app (https://splunkbase.splunk.com/app/1766/) has been bundled into this app.
SA-Shodan is now considered deprecated.

Updates for v 2.0.0:

  • IMPORTANT: This replaces the SA-Shodan app, which was originally a separate add-on. This is now merged into this app.
    If you have SA-Shodan already installed, it is recommended to remove that app.
  • The configuration page has been completely redone. It now uses a KV Store collection to add/update/delete IPs.
    You can enter either an IP or subnet.
  • If you do not have anything in the KV Store the dashboard will now warn you instead of throwing a Python error
    in the panels.
  • You no longer have to wait for the scheduled Shodan search to run in order to populate the JSON file.
    It will now update the file every time you make an edit on the configuration page.
  • The search command has changed from | shodan to | getshodan - see below under 'Searching'.
  • If you happen to be using the | shodan search command in any saved searches, reports,
Version 1.5.1
Feb. 1, 2018
  • Fixed issue where Shodan JSON population command failed on Windows environment.
Version 1.5
July 25, 2017
  • The IP/Subnet configuration page has been completely revamped.
  • Lookup of IP/Subnets have been replaced using a KV Store.
  • Dashboard will warn you if no IPs have been provided instead of simply throwing an elusive Python error.
Version 1.4
April 1, 2015

Fixed for 6.2 compatibility
Fixed a bug where the configuration screen would freak out when there are too many entries

Version 1.2
Sept. 25, 2014

Fixed dark.css so it actually shows the data in some readable font

Version 1.1
April 18, 2014

Make the python for the setup screen more...pythonic.

Version 1.0
April 17, 2014

Splunk 6 Only!
Initial Release

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.