Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
AbuseIPDB App app icon

AbuseIPDB App

The Official AbuseIPDB App for Splunk seamlessly integrates AbuseIPDB's IP threat intelligence API with Splunk, enabling you to quickly and accurately perform threat analysis on IP addresses and enrich IOCs. AbuseIPDB is the largest crowdsourced cyber threat intelligence platform, with over one million IP abuse reports processed daily. This integration adds several search commands that allow you to access the following functions: *Check IP Address*: Check IP addresses for abuse by returning an "abuseConfidenceScore" that represents how confident AbuseIPDB is that the given IP is abusive. *Check IP Block*: Check an entire subnet for abuse reports *Report IP Address*: Submit your own abuse report to AbuseIPDB, based on your own evidence *Download Abuse Reports*: Research an IOC by pulling in details of abuse reports made by others against an IP *Download Abuse Blacklist*: Download a customizable bulk list of the most actively abusive IPs from AbuseIPDB *Sync AbuseIPDB IP Blacklist to Splunk:* The app also allows you to set up a Splunk cron that will regularly download an up-to-date list of the most abusive IPs from the AbuseIPDB IP Blacklist into a Splunk KV Store, allowing easy construction of automations and workflows checking for abusive IPs that engage on your network. This app is actively under development by the AbuseIPDB team, and we plan to be rolling out additional useful features in the future.

splunk product badge

Latest Version 2.2.10
April 4, 2025
Compatibility
Not Available
Platform Version: 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 6.x, 5.x, 4.x
Rating

0

(0)

Log in to rate this app
Support
AbuseIPDB App support icon
Developer Supported app
Ranking

#19

in Reputation
The Official AbuseIPDB App for Splunk seamlessly integrates AbuseIPDB's IP threat intelligence API with Splunk, enabling you to quickly and accurately perform threat analysis on IP addresses and enrich IOCs. AbuseIPDB is the largest crowdsourced cyber threat intelligence platform, with over one million IP abuse reports processed daily. This integration adds several search commands that allow you to access the following functions: *Check IP Address*: Check IP addresses for abuse by returning an "abuseConfidenceScore" that represents how confident AbuseIPDB is that the given IP is abusive. *Check IP Block*: Check an entire subnet for abuse reports *Report IP Address*: Submit your own abuse report to AbuseIPDB, based on your own evidence *Download Abuse Reports*: Research an IOC by pulling in details of abuse reports made by others against an IP *Download Abuse Blacklist*: Download a customizable bulk list of the most actively abusive IPs from AbuseIPDB *Sync AbuseIPDB IP Blacklist to Splunk:* The app also allows you to set up a Splunk cron that will regularly download an up-to-date list of the most abusive IPs from the AbuseIPDB IP Blacklist into a Splunk KV Store, allowing easy construction of automations and workflows checking for abusive IPs that engage on your network. This app is actively under development by the AbuseIPDB team, and we plan to be rolling out additional useful features in the future.

Categories

Created By

Jonathan Weber

Type

app

Downloads

1,879

Resources

Login to report this app listing