Default Version 1.0.5
October 2, 2025
October 2, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x
Log in to rate this app
Most sourcetypes contain endpoint events of some sort. This app provides Splunk dashboards, forms, and reports which can be used to explore your endpoint events across your different sourcetypes. To do this, the app relies on the Splunk Common Information Model (CIM) for endpoint events. This means that the app can report on any endpoint data, as long as it has been on-boarded properly, and is available through the Endpoint data model.
Log in to report this app listing.