icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Ivanti Device and Application Control (IDAC) App for Splunk
SHA256 checksum (ivanti-device-and-application-control-idac-app-for-splunk_102.tgz) deb06336c0f9f5190aae04acd098d15327b565c93e05d971004052ab9fce9247 SHA256 checksum (ivanti-device-and-application-control-idac-app-for-splunk_101.tgz) 604b287a6df9d7eef051996fd33fc1d077cfa7055c8ac137140e3a920c1b6c52 SHA256 checksum (ivanti-device-and-application-control-idac-app-for-splunk_100.tgz) 65bfd9691866ee037b5e7092332dfa9c228a895edd2824c93f946ce345b5168c
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

Ivanti Device and Application Control (IDAC) App for Splunk

Splunk Cloud
This app is NOT supported by Splunk. Please read about what that means for youhere.
Overview
Details
The Ivanti Device and Application Control App for Splunk provides pre-built dashboards for IDAC data that is imported with the IDAC Add-on for Splunk.

The dashboards in this app expose both statistics and detailed views on all activities - blocks, shadowing, admin audit activity and agent updates.

Supported Versions of Ivanti Device and Application Control
- IDAC 5.3 (tested)
- Any version of IDAC that supports SIEM integration using adc_alp_[architecture].dll to either Windows event logs or flat file (.json) logs

Overview

The Ivanti Device and Application Control App for Splunk provides pre-built dashboards for IDAC data that is imported with the IDAC Add-on for Splunk.

The dashboards in this app expose both statistics and detailed views on all activities - blocks, shadowing, admin audit activity and agent updates.

An accompanying Technology Add-On (TA) provides properties (props.conf) and sample inputs (inputs.conf) to ingest and parse IDAC events.

Requirements

This app has been developed and tested against the latest release of Splunk available at the time of development: 8.1.3. The app should work on Splunk 7.x without any issues.

Installation

Install the Ivanti IDAC App for Splunk on search heads for dashboards and CIM-compliant field aliases.

Edit the idac_index macro to specify which Splunk index is used to store the IDAC event data; by default this macro is set to index=idac.

For ingestion of device control event data, install the IDAC TA (https://splunkbase.splunk.com/app/5532/) where data from IDAC is first parsed - heavy forwarders, or indexers if no heavy forwarder is used between a universal forwarder (on the IDAC server) and the indexing tier.

Configuration

Ensure that users of the app are members of a role configured to search, by default, the relevant index containing ivanti:idac:* events.

Support

For support, please raise a support call with Ivanti: https://www.ivanti.com.au/support/contact

Products Supported

  • IDAC 5.3 (tested)
  • Any version of IDAC that supports SIEM integration using adc_alp_<architecture>.dll to either Windows event logs or flat file (.json) logs

Authors

Intalock (www.intalock.com.au/)

  • Greg Ford

Release Notes

Version 1.0

v1.0

  • Initial version

Release Notes

Version 1.0.2
May 24, 2021

Version 1.0.1
May 21, 2021

Added drilldowns to main dashboard.

Version 1.0.0
May 6, 2021

2
Installs
15
Downloads
Share Subscribe LOGIN TO DOWNLOAD

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.