Latest Version 1.0.1
December 28, 2020
This app is archived. App archiving documentation
King & Union's Avalon Add-On for Splunk enables the interchange of data between Avalon and Splunk to support security investigations leveraging both platforms. The add-on provides custom search commands that allow for both the creation and update of Avalon workspaces from a Splunk search, as well as the retrieval of node and workspace data on demand. All add-on activities, to include details about workspaces and nodes, are visible in the Avalon Summary dashboard. Retrieved data can be filtered and configured for inclusion in a Splunk ES instance as a custom threat feed for further alerting.
(2)
Categories
Created By
Type
Downloads
Splunk Answers
Ask a question about this app listing(Opens new window)Resources