The Endace App for Splunk SOAR receives events forwarded from a Splunk Enterprise instance, which are then parsed by the provided playbooks to search for packets of interest on an EndaceProbe fabric. When matching packets are found, these can be automatically downloaded and analyzed, or archived as PCAP files.
(0)
Supported Actions
Categories
Created By
Source Code
Type
Downloads
Licensing
Splunk Answers
Resources