Skip to main content
Warning
This app is archived. App archiving documentation
IBM Resilient/SOAR Splunk Add-on app icon

IBM Resilient/SOAR Splunk Add-on

The Resilient app integrates the IBM Resilient SOAR Platform with Splunk to simplify and streamline the process of escalating and managing incidents. Escalating a Splunk alert or Splunk ES notable event to the Resilient platform allows the platform to generate a detailed, incident-specific response plan that enables security team members to quickly respond.Built by IBM Resilient
splunk product badge

Default Version 1.3.2

June 14, 2022

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x

Rating
2
(3)

Log in to rate this app

Support
Archived Add-on

The Resilient app integrates the IBM Resilient SOAR Platform with Splunk to simplify and streamline the process of escalating and managing incidents. Escalating a Splunk alert or Splunk ES notable event to the Resilient platform allows the platform to generate a detailed, incident-specific response plan that enables security team members to quickly respond. Additionally, security team members can add artifacts and other incident details to incident records, and can leverage built-in threat intelligence to gather valuable context needed to inform an intelligent and decisive response. Complete documentation is available on GitHub: https://github.com/ibmresilient/resilient-reference/tree/master/developer_guides/resilient-splunk-addon For support, please visit https://ibm.com/mysupport . Do not use the "Contact Developer" link, as that email address is not monitored.