Welcome to the new Splunkbase! To return to the old Splunkbase, click here.
TA-guardium_api app icon

TA-guardium_api

IBM Guardium REST API Add-on for Splunk enables secure, automated ingestion of database activity and audit logs from IBM Guardium into Splunk using the Guardium online_report REST API.

Built by
splunk product badge
screenshot
screenshot

Latest Version 1.0.0
December 7, 2025
Compatibility
Not Available
Platform Version: 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
CIM Version: 6.x, 5.x
Rating

0

(0)

Log in to rate this app
Support
TA-guardium_api support icon
Developer Supported addon
IBM Guardium REST API Add-on for Splunk enables secure, automated ingestion of database activity and audit logs from IBM Guardium into Splunk using the Guardium online_report REST API. This add-on provides a fully checkpointed, fault-tolerant modular input that continuously pulls SQL activity data at a configurable interval and resumes seamlessly after restarts without duplicating events. It supports per-input Guardium API URLs, central token-based authentication, optional SSL verification, and scalable pagination for high-volume environments. All ingested events are structured as JSON and can be easily normalized to the Splunk Common Information Model (CIM) Database data model for use with Enterprise Security, custom dashboards, and compliance reporting. This add-on is ideal for organizations that rely on IBM Guardium for database security monitoring and want centralized analytics, detection, and long-term retention in Splunk.

Categories

Created By

Efheem P

Type

addon

Downloads

12

Resources

Log in to report this app listing