Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
CCX Add-on for Cisco Identity Services (ISE) app icon

CCX Add-on for Cisco Identity Services (ISE)

About Us: CyberCX is Australia’s greatest force of cyber security experts. Our highly skilled professional services team operates a 24x7 on-shore security operations centre (SOC) servicing corporate and public sector organisations across Australia and New Zealand, specialising in Security Operations services leveraging Splunk. Description: CCX Security Operations has taken it upon ourselves to update and improve the existing Splunk Add-on for Cisco Identity Services to ensure it is as CIM compliant as possible. This TA was built using a large dataset and endeavours to be the most CIM compliant comprehensive field extraction TA available for Cisco ISE. The Technical Addon is to be used on Search Heads and Splunk Heavy Forwarders. Features: - This TA currently supports logtypes tagged under the following CIM datamodels: Alerts, Authentication, Change, Certificates, Endpoint, Intrusion Detection, Network Session, Network Traffic, and Vulnerabilities. Attribution: CyberCX acknowledges the foundation work done by the Splunk Inc. team to provide this TA.

splunk product badge

Latest Version 1.0.3
July 4, 2024
Compatibility
Not Available
Platform Version: 9.4, 9.3, 9.2, 9.1
CIM Version: 5.x, 4.x
Rating

0

(0)

Log in to rate this app
Support
CCX Add-on for Cisco Identity Services (ISE) support icon
Developer Supported addon
Ranking

#34

in SIEM
About Us: CyberCX is Australia’s greatest force of cyber security experts. Our highly skilled professional services team operates a 24x7 on-shore security operations centre (SOC) servicing corporate and public sector organisations across Australia and New Zealand, specialising in Security Operations services leveraging Splunk. Description: CCX Security Operations has taken it upon ourselves to update and improve the existing Splunk Add-on for Cisco Identity Services to ensure it is as CIM compliant as possible. This TA was built using a large dataset and endeavours to be the most CIM compliant comprehensive field extraction TA available for Cisco ISE. The Technical Addon is to be used on Search Heads and Splunk Heavy Forwarders. Features: - This TA currently supports logtypes tagged under the following CIM datamodels: Alerts, Authentication, Change, Certificates, Endpoint, Intrusion Detection, Network Session, Network Traffic, and Vulnerabilities. Attribution: CyberCX acknowledges the foundation work done by the Splunk Inc. team to provide this TA.

Categories

Created By

Henrique Linsmeyer

Type

addon

Downloads

895

Resources

Login to report this app listing