icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Technology Add-on for Webex Teams
SHA256 checksum (technology-add-on-for-webex-teams_101.tgz) 8c3e740bbce0cfab7668bd627d6d730f172e38f7abbd7e7794b223deb6ddbe1d SHA256 checksum (technology-add-on-for-webex-teams_100.tgz) aefc5f831ee8989b0176a2b55ccb836b879ef4bd11e6501c9e106448b7ddf040
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Technology Add-on for Webex Teams

Splunk AppInspect Passed
Admins: Please read about Splunk Enterprise 8.0 and the Python 2.7 end-of-life changes and impact on apps and upgradeshere.
Webex Teams Modular Input built by Datapunctum GmbH

The purpose of this add-on is to collect Webex Teams Events and Webex Teams Audit-Events through the Webex Teams API (https://developer.webex.com/docs/api/getting-started)

See README.txt for instruction how to use the add-on.

This Add-on has been built using the Splunk Add-on Builder

Webex Teams Modular Input

Authors: Datapunctum GmbH
Description: Webex Teams Modular Input
Version: 1.0.1


The purpose of this add-on is to collect Webex Teams Events and Webex Teams Audit-Events through the Webex Teams API

This Add-on has been built using the Splunk Add-on Builder

Special Features

  • If files have been uploaded in a message, the event can be enriched with file information.
  • If rooms have been created, the event can be enriched with the room title.
  • Messages can be masked for privacy


Authentication to the API is through Personal Access Tokens. An Personal Access Token can be acquired through a Refresh Token, which has to be renewed once a while.

The Add-on expects an active Refresh Tokens and keeps track of the lifetime of the Access Token and automatically refreshes the access token if needed.

Additionally to the Refresh Token, the Client ID and Client Secret has to be provided.

Multiple Refresh Tokens with different access rights.(up to 4) may be configured and referenced by Inputs.

Additional Configuration


The Log-Level can be set in the "Logging" Tab.

Log Files can be found under:

  • $SPLUNK_HOME/var/log/splunk/ta_dp_webex_teams_webex_teams_events.log for Events

  • $SPLUNK_HOME/var/log/splunk/ta_dp_webex_teams_webex_teams_admin_audit_events.log for Audit Events

General Configuration

In some cases, the Webex API did not give back a valid certificate. For all requests, it's possible to disable Certificate Verification.


For connections over a proxy, the settings can be found under "Configuration"

Input Configuration


Under Inputs, select which type of input should be created

Creating Webex Teams Event Inputs

Following parameters have to be set for the input:

  • Name
  • Interval
  • Index
  • Refresh Token
  • Resource
  • Message Masking
  • Fetch Attachemen Information
  • Fetch Room Information

Events will be created with the webex:teams:events sourcetype.

Creating Webex Teams Admin Audit Event Input

Following parameters have to be set for the input:

  • Name
  • Interval
  • Index
  • Refresh Token
  • Organization ID

Events will be created with the webex:teams:adminaudit:events sourcetype.


Copyright 2020 Datapunctum GmbH

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at


Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
See the License for the specific language governing permissions and
limitations under the License.

Sourcecode Repository


Release Notes

Version 1.0.1
Aug. 4, 2020

1.0.1 / 2020-08-04 Bugfix Release
* Fixed in issue with too many token refreshes

Version 1.0.0
July 25, 2020


Subscribe Share

AppInspect Tooling

Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
© 2005-2020 Splunk Inc. All rights reserved.
Splunk®, Splunk>®, Listen to Your Data®, The Engine for Machine Data®, Hunk®, Splunk Cloud™, Splunk Light™, SPL™ and Splunk MINT™ are trademarks and registered trademarks of Splunk Inc. in the United States and other countries. All other brand names, product names, or trademarks belong to their respective owners.