icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Cyences App for Splunk
SHA256 checksum (cyences-app-for-splunk_180.tgz) 3cad38491f6b78559663075a30139bcd87514d15a5766c53c7dbf01070551f43 SHA256 checksum (cyences-app-for-splunk_170.tgz) 201ca56346445994e60edb415666666db90d6160165942aca7832666cd1a28c8 SHA256 checksum (cyences-app-for-splunk_161.tgz) f8ed8bc64b9181d3f51e4b1f87f87d417b1f7c57a82c025177944d039bf5bf6f SHA256 checksum (cyences-app-for-splunk_150.tgz) cbaa0442de251cdc42e181ff74b7401b24a0b165ece3436d145f6b8d1998fe14 SHA256 checksum (cyences-app-for-splunk_140.tgz) 38b9e9f0c4651767f4aa49bed75e013d847648425dec4b8f3c599146404dcd71 SHA256 checksum (cyences-app-for-splunk_130.tgz) 81c1ce2f14b202dd75fab548ae833c92dd87ecd1e1648fdedc4b2ae2789de814 SHA256 checksum (cyences-app-for-splunk_120.tgz) c470c3966cd5f771b7f5e40a73831c1e7fb394762ea3bea8dfa6c95d34633fa7 SHA256 checksum (cyences-app-for-splunk_110.tgz) aa7c7822029b9bf750cffc683e7eca397c31777904ee136de37b9b991821dbd9 SHA256 checksum (cyences-app-for-splunk_100.tgz) 939468a67b5e86ebfb4e7f328873e900fadc396cee1d97775571ee093d11097b
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


Cyences App for Splunk

Splunk Cloud
The Cyences App for Splunk was designed to allow users complete visibility of their system's security status. It was created with the intention of becoming a seamless piece of the Blue team arsenal; continuous quarterly enhancements are occurring towards achieving that goal.

This app contains useful security alerts, reports, and dashboards. Here are some of the categories that are covered by Cyences: Ransomware, Active Directory & Windows, Linux/Unix, Office 365 (O365), AWS (Amazon Web Services), G Suite (Google Workspace), Endpoint Compromise, Network Compromise, Credential Compromise, Sophos, Windows Defender, CrowdStrike, Palo Alto Firewall (PaloAlto), VPN (Global Protect and FortiGate) and Authentication reports.
It also contains a Forensic dashboard for investigating security issues.
It also contains some intelligence dashboards: Asset Intelligence, Device Inventory (renamed from Device Master Table), Lansweeper, Malicious IP List, Qualys, and Tenable.

Refer to the Details page for the documentation link.

Refer https://cyences.com/cyences-app-for-splunk/ for documentation of the App.

Please provide your feedback and follow our progress on the App on the Cyences Forum - https://cyences.com/

GitHub repo of the App - https://github.com/VatsalJagani/Splunk-Cyences-App-for-Splunk

Overview dashboard
Forensic dashboard
Active Directory
Office 365 (O365)
AWS (Amazon Web Services)
G Suite (Google Workspace)
Endpoint Compromise
Network Compromise
Credential Compromise
Sophos Antivirus
Windows Defender Antivirus
CrowdStrike Antivirus
Palo Alto Firewall (PaloAlto)
VPN (Global Protect and FortiGate)
Authentication reports
* Splunk Admin

Intelligence Dashboards
Globally Detected Malicious IP List
Device Inventory
Asset Intelligence

Release Notes

Version 1.8.0
Sept. 21, 2021

See Documentation for full release notes and upgrade guide.

Version 1.7.0
Aug. 27, 2021

See Documentation for full release notes and upgrade guide.

Version 1.6.1
July 26, 2021
  • Bug Fix: The link of the Linux Dashboard was not working on Overview Dashboard. (Update from 1.6.0 to 1.6.1)
  • See Documentation for full release notes and upgrade guide.
Version 1.5.0
June 21, 2021

See Documentation for release notes.

Version 1.4.0
May 11, 2021

See Documentation for release notes.

Version 1.3.0
April 6, 2021

See Documentation for release notes and upgrade guide. Make sure to visit the release notes and upgrade guide before you upgrade the App.

Version 1.2.0
March 9, 2021

See Documentation for release notes and upgrade guide. See the link to the documentation page on the details page.

Version 1.1.0
Jan. 29, 2021

See the Details page for release notes and upgrade guide.

Version 1.0.0
Nov. 25, 2020

Version 1.0.0 (Nov 2020)
Created App Overview dashboard.
Added Details/Forensic dashboard for investigating security issues.
Added multiple security alerts with below categories.
* Categories: Ransomware, Active Directory & Windows, Office 365, Endpoint Compromise, Network Compromise, Credential Compromise, Sophos and Palo Alto Firewall.
Added below reports:
* Active Directory & Windows
* O365
* Network Reports
* Palo Alto
* Globally Detected Malicious IPs
* Sophos
* Authentication
Added App configuration dashboard.
Added HoneyDB based blocked IP list and used that list to identify bad traffic.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.