Skip to main content
SafeBreach Add-on for Splunk app icon

SafeBreach Add-on for Splunk

The SafeBreach Add-on for Splunk allows users to collect data from SafeBreach platform, either via API or the Syslog CEF outbound integration. The SafeBreach Add-on for Splunk collects simulation results and audit logs, then transforms and saves the data in CIM-compatible fields. The saved data can be consumed by running searches and creating manual correlations for the simulation results, or using the SafeBreach App for Splunk Enterprise, which provides dashboards for visual representation of the data. In addition, SafeBreach Insights can be fetched via API for later visualization of the security gaps discovered by SafeBreach simulations, as well as for generation of Notable events per SafeBreach Insight that can be consumed in Splunk ES application.Built by SafeBreach Inc
splunk product badge

Default Version 2.5.0

June 17, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 8.x, 6.x, 5.x, 4.x

Rating
5
(3)

Log in to rate this app

Support
Developer Supported

The SafeBreach Add-on for Splunk allows users to collect data from SafeBreach platform, either via API or the Syslog CEF outbound integration. The SafeBreach Add-on for Splunk collects simulation results and audit logs, then transforms and saves the data in CIM-compatible fields. The saved data can be consumed by running searches and creating manual correlations for the simulation results, or using the SafeBreach App for Splunk Enterprise, which provides dashboards for visual representation of the data. In addition, SafeBreach Insights can be fetched via API for later visualization of the security gaps discovered by SafeBreach simulations, as well as for generation of Notable events per SafeBreach Insight that can be consumed in Splunk ES application.