This Add-on version works with the following VMRay Platform versions: 4.0 and up.
This new Splunk Enterprise Add-on for the VMRay Platform replaces the legacy VMRay Analyzer Add-on.
Analysis Report Data, including VTIs and IOCs, is now parsed from the latest Summary.json v2.
A new event structure and format for optimal processing is now provided.
This new Add-on works with the following VMRay Platform versions: 4.0, 4.1, 4.2.
Note: The new event structure is not compatible with the legacy Add-on, so both versions should be installed at the same time, to ensure a smooth transition to the new Add-on.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.