Skip to main content
Warning
This app is archived. App archiving documentation
InQuest Addon for Splunk app icon

InQuest Addon for Splunk

The Splunk Addon for InQuest allows a Splunk® Enterprise administrator to search and build visualizations and alerts for InQuest device logs.Built by Michael Arcamone
splunk product badge

Default Version 1.0.0

October 18, 2017

Compatibility

Splunk Enterprise

CIM Version: 4.x

Rating
5
(3)

Log in to rate this app

Support
Archived Add-on

The Splunk Addon for InQuest allows a Splunk® Enterprise administrator to search and build visualizations and alerts for InQuest device logs. This technology addon includes CIM-compatible mappings and CEF extractions for InQuest syslog output. InQuest (http://www.inquest.net/) offers an on-premise network-based security solution that inspects application content over the most commonly used network protocols and performs Deep File Inspection (DFI) capable of detecting malware as it passes through your traditional security defenses.