Default Version 1.0.2
August 10, 2025
August 10, 2025
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2
Log in to rate this app
Pulls down Thinkst Canary audit logs using the API. Install on Splunk Cloud IDM or a heavy forwarder. Can also be installed on Search heads for the sourcetypes, but its clearer if you just create the sourcetype canarytools:audit manually with KV_MODE = none. Icon from https://www.vecteezy.com/vector-art/1919479-linear-audit-document-icons-design-isolated-on-white-background https://github.com/Bre77/TA_thinkst_canary_audit
Log in to report this app listing.