icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Varonis DatAlert App for Splunk
SHA256 checksum (varonis-datalert-app-for-splunk_22.tgz) b505bee727228970537ca2710a19c7a9299595f1feebb2d86a1695b7842d8b22 SHA256 checksum (varonis-datalert-app-for-splunk_21.tgz) 95ce465e947ddfd54c98e3e212e6f3bbc8130b703b34005f44c7cda3d1460789 SHA256 checksum (varonis-datalert-app-for-splunk_20.tgz) 6eac07baa2087ad7cb26aad70a2b863b85977347a9ddb8ea9d2f96689146fa13 SHA256 checksum (varonis-datalert-app-for-splunk_115.tgz) 737e48441082798cd439714d69a522441ef61b22abb9f102e03bf139be16b208 SHA256 checksum (varonis-datalert-app-for-splunk_114.tgz) c4ceb50c997c43c13758951e484f44b22e8c9b3323f497056172446b62865c93 SHA256 checksum (varonis-datalert-app-for-splunk_113.tgz) 600faa0bb68b341ef3e3b0793653168e1967474457d4b5065a1d0bf2bb59c165 SHA256 checksum (varonis-datalert-app-for-splunk_111.tgz) 3ef9baaa1f5205f0749f6015af3d5f6cc4aec7acb6a99d3f0fcba2bf0111fb06 SHA256 checksum (varonis-datalert-app-for-splunk_11.tgz) 8528f0817fda5842943cc034ec5f2f69dc4b45e857b1c610dec7100dc0f26506 SHA256 checksum (varonis-datalert-app-for-splunk_10.tgz) 762d570599b796ea2868e209aa3baefa6f97f860708b0ab8eb166354b5c74f10
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Varonis DatAlert App for Splunk

Overview
Details
The Varonis DatAlert App for Splunk® enables integrating the Varonis DatAlert functionality into Splunk Enterprise. Using the app's dashboards, you can locate notable Varonis alerts directly from the Splunk user interface, and then drill down into Varonis DatAlert to get additional insights into the alert and the context in which it was generated. Additionally, the app includes field extractions that assist users in querying and visualizing Varonis alerts using Splunk Enterprise and that enable correlating the Varonis alerts with other events collected by Splunk Enterprise.

If you find any issues, use the app Splunk Answers forum or contact Varonis support.

Note: The Varonis Technology Add-On for Splunk must be installed in order for the App to pull data. Download here: https://splunkbase.splunk.com/app/4256

For more information, refer to the user guide or contact Varonis support.

Release Notes

Version 2.2
Nov. 14, 2018

New for Version 2.2:
* Fixed Fonts for Splunk versions <= 7.1

Version 2.1
Nov. 1, 2018

New for Version 2.1:
* Fixed URL bug (linking between dashboards)

Version 2.0
Oct. 22, 2018

New for version 2.0:
* Added support for Splunk CIM (implemented as part of the Technology Add-on)
* Moved all parsing to our Technology Add-on (which is now required install for the App to work)
* Updated App styling to match DatAlert Web UI
* Fixed display of double backslashes

Version 1.15
Nov. 30, 2017

Bug fixes

Version 1.14
Sept. 7, 2017

* Bug fix: Changed field extractions to use duser instead of samAcc (field extraction didn't work correctly with duser containing spaces and commas)
* Changed source type to follow Splunk's new guidelines (from "dls-cef-alerts" to "varonis:dls:alerts"). Note that events with the older source type are still supported and included in the dashboards.
* Added 'alt' app icons visible in the app menu

Version 1.13
Sept. 6, 2017

New for version 1.13:
* Bug fix: Changed field extractions to use duser instead of samAcc (field extraction didn't work correctly with duser containing spaces and commas)

New for version 1.12 (internal, incorporated in 1.13):
* Changed source type to follow Splunk's new guidelines (from "dls-cef-alerts" to "varonis:dls:alerts"). Note that events with the older source type are still supported and included in the dashboards.
* Added 'alt' app icons visible in the app menu

Version 1.11
May 10, 2017

* Performance improvements
* Implementing the index macro per Splunk best practices

Version 1.1
May 9, 2017

* Performance improvements
* Implementing the index macro per Splunk best practices

Version 1.0
April 20, 2017

Initial beta release

154
Installs
769
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2019 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.