Skip to main content
Warning
This app is archived. App archiving documentation
URL Expander for Splunk app icon

URL Expander for Splunk

URL Expander safely retrieves the real location of shortened links, potentially unmasking malicious urls.Built by James Sheppard
splunk product badge

Default Version 1.1

February 9, 2017

Compatibility

Splunk Enterprise

Rating
4
(4)

Log in to rate this app

Support
Archived App

URL Expander safely retrieves the real location of shortened links, potentially unmasking malicious urls. Core Features: - Expanding links masked by URL shortening services. - Following/limiting redirect chains (ie. redirects that lead to more redirects) - Low-level proxy capabilities for hiding your origin (if desired) - Specifying a useragent string for use in retrieving URLs URL Expander was built with security analysts in mind, specifically for use with log data containing shortened links where the actual location isn't revealed in the logs. For example, some email appliances may scan incoming emails for hyperlinks, but if any of those hyperlinks are short URLs, the real location may not be specified in the logs.