icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Digital Guardian App for Splunk Enterprise
SHA256 checksum (digital-guardian-app-for-splunk-enterprise_203.tgz) e2f3c54b88e8180ef98e8112a0e0d9f2019c8a62dd0e9886b0ca24475ccb9561 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_202.tgz) b94af2946427b3225e500b53b99d8e21c25734d80dcf16f2c8b4b3bd892a2897 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_201.tgz) 56869d5435944bef6a2df4b47fbced2a6af3791617737e0d670341d61a43454f SHA256 checksum (digital-guardian-app-for-splunk-enterprise_200.tgz) 76faba0775d70d6fb4b20744f2d016edc5fb0eb18162cb4e903985b66dd464d1 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_130.tgz) 1c11e7c05e18e94c5135b30f4ca9b153281537334e49e0177f68df52d3fe83a3 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_125.tgz) 366a803172cec17b117902fa38401e709c449c0a4caff52d7a169976f19790d9 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_124.tgz) dc011a220a92036e7b88658dccadc2efda630cf043e4b78e54d4f998f2780285 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_123.tgz) 445d49892e1326c7c79fb62bfe177d6f08aaeb88839a07392737e5dafabf453b SHA256 checksum (digital-guardian-app-for-splunk-enterprise_122.tgz) 3a34da745562789046255a81a932723bd291b1e9c1da077eb394faf50ade80bb SHA256 checksum (digital-guardian-app-for-splunk-enterprise_121.tgz) 73548a921a4ea5fdd99d79d1752494d35990d4d03d8be62b2f959ef630691cdc SHA256 checksum (digital-guardian-app-for-splunk-enterprise_12.tgz) 2b69e907f33c320e187d112478460153ff76b02993dbb85809256e1523acf177 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_11.tgz) c271db6975dc58fe638a77a488dd2f9dfd2760cc3a6c28ca4e77781b76cacb6f SHA256 checksum (digital-guardian-app-for-splunk-enterprise_101.tgz) 2269eefbbf336e80aa2306c4808d2dd1f37066fb70802957cdebd75ec8140d9a SHA256 checksum (digital-guardian-app-for-splunk-enterprise_10.tgz) 14fdbb136337621db6afe9e10cd8b301717a34d42bb80b165523793368b1b304
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Digital Guardian App for Splunk Enterprise

This app is NOT supported by Splunk. Please read about what that means for youhere.
Overview
Details
Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App works with the Digital Guardian Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

Introduction

A Splunk Application to get insight from your Digital Guardian implementation.

Installation

  1. Install the TA
  2. Move digitalguardian_web folder to your Search Head (manually or through deployment server)
  3. Restart Search Head
  4. When you go to the app for the first time, you will fill out some fields. You may need to restart after you complete setup if you see some searches not working.

Usage

Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App includes an Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

The Digital Guardian App for Splunk Enterprise includes seven dashboards that visualize Digital Guardian events and alerts with advanced abilities to drill down and filter data to pinpoint threats, investigate and respond. Dashboards include:

  • Data Classification: Show that sensitive data is effectively identified and classified
  • Alerts: Monitor policy violations, validate appropriate controls are in place and provide input into incident response process
  • Events: Monitor data leaving the enterprise by channel - Email, Print, Removable Devices and Network Uploads. Understand channel usage to establish risk level.
  • Process: Monitor process (application) access to data and identify anomalies
  • Data Egress: Monitor data movement to understand how and where data is put at risk to improve classification and controls
  • Advanced Threat Detection: Monitor malware alerts resulting from behavioral detection rules in Digital Guardian’s advanced threat module
  • Operations: Monitor operations of the Digital Guardian IT infrastructure

Release Notes

Version 2.0.3
Feb. 9, 2018

2.0.3 - 2/8/2018
* Removed extra javascript
* Fixed file permissions

Version 2.0.2
Jan. 10, 2018

Version 2.0.1
Feb. 23, 2017

2.0.1 - 2/23/2017
* Updated README

Version 2.0.0
Feb. 10, 2017

2.0.0 - 2/10/2017
* Updated for use with Splunk 6.5 and later.
* Can be used with Splunk 6.4.x, but backward compatibility before that is not guaranteed.
* Bug Fixes
* Requires Digital Guardian 7.0.0 or above

Version 1.3.0
June 4, 2015

Version 1.3.0 of the Digital Guardian App for Splunk Enterprise includes the following new changes:
* Moved lookups to TA
* Added Investigation Page
* Added Email and NTU pages
* Bug Fixes

Version 1.2.5
Jan. 15, 2015

1.2.5 - 1/15/2015
* Fixed issue with Drive Type Lookups
* Fixed issue with Data Egress Page related to Event Types

Version 1.2.4
Dec. 24, 2014

1.2.4 - 12/24/2014
* Fixed issue with Network Direction Lookup

Version 1.2.3
Dec. 24, 2014

1.2.3 - 12/24/2014
* Fixed issue with extensions search on events page for new chart includes
* Fixed base search to allow extension includes
* Backslash escaping to allow for better drilldowns.

Version 1.2.2
Dec. 23, 2014

1.2.2 - 12/23/204
* Fixed issue with base search for new charts on events page.

Version 1.2.1
Dec. 23, 2014

1.2.1 - 12/22/2014
* Fixed issue with Wildcard search changing search button name on click
* Fixed rendering issue with new charts on events page.
* Added Computer Type Lookup to application

Version 1.2
Dec. 19, 2014

Version 1.1
Nov. 23, 2014

App updated to use codes and lookups for String values across most of the app.

Version 1.0.1
Oct. 21, 2014

- Fixed Issue with 404 Error sometimes appearing after install.

Version 1.0
Oct. 2, 2014

130
Installs
1,331
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.