Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Recorded Future App for Splunk
MD5 checksum (recorded-future-app-for-splunk_2627.tgz) 1342dc0935f67b4d7089110af169d002 MD5 checksum (recorded-future-app-for-splunk_2331.tgz) ede529ead14c55644013fbe21bb14822 MD5 checksum (recorded-future-app-for-splunk_2221.tgz) 4a272f3d6f868f2325ba3ff8b2317c73 MD5 checksum (recorded-future-app-for-splunk_11111.tgz) 958b3755ad4e08629636094db6d2d84b MD5 checksum (recorded-future-app-for-splunk_11029.tgz) db703dee9d29a74031ff46fd565aba8a MD5 checksum (recorded-future-app-for-splunk_11016.tgz) 112032ffece39a0532e061e6a7f8c4b5
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Recorded Future App for Splunk

Overview
Details
Make fast and informed incident verdicts, expand detection incidents in your network, and use Recorded Future to monitor emerging external threats to your organization.

Recorded Future for Splunk brings real-time threat intelligence directly into Splunk, giving SOC analysts context with full transparency. Our indicator risk information shows analysts the evidence supporting risk assessments to confirm verdicts of malicious incidents. This helps analysts prioritize which events to review so they spend their time on the incidents that matter most.

Installation

To install the Recorded Future App for Splunk:
1. Download the App from Splunkbase
2. In Splunk, select “Install app from file” under “Manage Apps”
3. On the next page, select “Upload App” and then “Choose File”
4. Browse to the location of the file and select it. Then upload the file.
5. A restart of the Splunk instance will be required once the installation has completed.

Alternately, you can download the App using the Splunk web interface "Find more apps online" feature.

You can also uncompress the App in $SPLUNK_HOME/etc/apps directory and restart Splunk.

Set Up

After installation, you will need to set up the Recorded Future App for Splunk to communicate with the Recorded Future API.

Contact Us

For more information and to set up your trial or paid subscription, please contact
splunk@recordedfuture.com

Release Notes

Version: 2.6.27

Summary:

- Hash Enrichment dashboards now take advantage of lightweight hash queries.
- Updated IP Risk List download

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

June 27, 2016, 11:10 a.m.

Platform Independent

6.4, 6.3, 6.2

Version: 2.3.31

Summary:
- new getting started dashboard
- added risk evidence and scores to hash enrichment dashboard
- bug fixes

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

April 4, 2016, 1:27 a.m.

Platform Independent

6.4, 6.3, 6.2

Version: 2.2.21

Summary: improved risk evidence and scores for on-demand enrichment

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

Feb. 22, 2016, 1:48 a.m.

Platform Independent

6.3, 6.2

Version: 1.11.11

Summary: minor bug fix to IP Enrichment dashboard for distributed environments.

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

Nov. 12, 2015, 7:04 p.m.

Platform Independent

6.3, 6.2

Version: 1.10.29

Summary: minor bug fix to IP Enrichment dashboard for distributed environments.

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

Oct. 29, 2015, 8:13 p.m.

Platform Independent

6.3, 6.2

Version: 1.10.16

Summary: presentation improvements to dashboards and bug fixes.

1. CHANGE: Simplified installation settings
2. CHANGE: Heatmap color-coding added to these dashboards:
Log Correlations, IP Monitoring, Domain Monitoring, Current Threat Trends
3. FIX: Corrected rf_hits macro syntax within macros.conf file
4. FIX: Disabled search drilldown from enrichment dashboards

For more detailed releases notes, please read the CHANGELOG file packaged with this add-on.

Oct. 16, 2015, 7:31 p.m.

Platform Independent

6.3, 6.2

20
Installs
607
Downloads
Share Subscribe LOGIN TO DOWNLOAD
Version
2.6.27
Category
Security, Fraud & Compliance
Product Support
Splunk Enterprise
Content Type
App
Splunk Versions
6.4
6.3
6.2
Licensing
BSD 3-Clause
Platforms
Platform Independent
Built by
Recorded Future
Contact Developer
Subscribe Share

Splunk Certification Program

Splunk's App Certification program uses a specific set of criteria to evaluate the level of quality, usability and security your app offers to its users. In addition, we evaluate the documentation and support you offer to your app's users.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2017 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.