icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.
Splunkbase will be undergoing a scheduled migration and will be unavailable on Saturday, Oct 1, 2022, from 11AM to 3PM PDT

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Amazon GuardDuty Add-on for Splunk
SHA256 checksum (amazon-guardduty-add-on-for-splunk_104.tgz) de18629dcf3e507cb676af42d64aa02e4142253465f4fec70b93462f0426f2be SHA256 checksum (amazon-guardduty-add-on-for-splunk_103.tgz) 4308d4fe5dd683317f108e6889664f8dfb15e625d70292bbfbe5b779e081c4da SHA256 checksum (amazon-guardduty-add-on-for-splunk_102.tgz) 42830341ed97f3357be9d746058d9ac4aea48296c9224a4952c264f2c048d879
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


Amazon GuardDuty Add-on for Splunk

Splunk Labs
This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
The Amazon GuardDuty Addon provides knowledge objects for GuardDuty data via Amazon CloudWatch Events. This Add-on is meant to compliment the existing Splunk Add-on for Amazon Web Services (https://splunkbase.splunk.com/app/1876/). There are also two dashboards included that are dependent upon the Splunk App for AWS (https://splunkbase.splunk.com/app/1274/) and Splunk Add-on For Amazon Web Services.

*** The Amazon GuardDuty Add-on is not compatible with the Splunk Add-on for Amazon Kinesis Firehose

Amazon GuardDuty Addon and Dashboards

What is GuardDuty?

Amazon GuardDuty, announced at re:invent 2017, is a continuous security monitoring service that requires no customer-managed hardware or software. GuardDuty analyzes and processes Amazon VPC Flow Logs and Amazon CloudTrail event logs. GuardDuty uses security logic and AWS usage statistics techniques to identify unexpected and potentially unauthorized and malicious activity. This can include issues like escalations of privileges, uses of exposed credentials, or communication with malicious IPs, URLs, or domains.
GuardDuty informs you of the status of your AWS infrastructure and applications by producing security findings that you can view in the GuardDuty console or through Amazon CloudWatch


A short video that walks through pushing CloudWatch Events generated by GuardDuty to Splunk is available here. Note that these events are delivered to Splunk over HTTP Event Collector


The "TA" is purely for storing KOs to make the specific dashboards work - it does not handle data collection. Since these are CloudWatch Events, both the AWS Lambda Blueprints and SQS-based Mod-Input in Splunk_TA_aws are sufficient.

Both simplexml dashboards (guard_duty.xml and guard_duty2.xml) are examples that can be integrated into the existing splunk_app_aws or extended for your own use.

Release Notes

Version 1.0.4
April 5, 2018

Minor updates to props.conf to resolve dashboard issues resulting from field name collisions,

Version 1.0.3
March 26, 2018

Minor fix to example dashboards.

Version 1.0.2
Dec. 21, 2017

Updates to props, tags and eventtypes to support the "Alerts" and "Intrusion Detection" datamodels.

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.