April 25, 2026
Suricata SOC Investigation
Splunk app for investigating Suricata alerts with dashboards, anomaly detection, MITRE mapping, and SOC-focused analysis workflows.Built by Kaled AljeburDefault Version 1.1.1
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Rating
0(0)
Log in to rate this app
Support
Developer Supported
Suricata SOC Investigation is a Splunk app for investigating Suricata IDS and IPS alerts through analyst-focused dashboards, correlation views, anomaly detection, and ATT&CK-aligned context. It helps SOC teams move beyond basic alert counts by providing workflows for triage, attack-story reconstruction, target risk scoring, MITRE mapping, and alert-driven investigation. The app is designed for security analysts who ingest Suricata data into Splunk and need a practical investigation experience built around detection review, prioritization, and response-oriented analysis.
Categories
Investigative, SIEM
Created by
Kaled Aljebur
Source code
Type
app
Downloads
183
Splunk Answers
Resources
Log in to report this app listing.