Skip to main content
Suricata SOC Investigation app icon

Suricata SOC Investigation

Splunk app for investigating Suricata alerts with dashboards, anomaly detection, MITRE mapping, and SOC-focused analysis workflows.Built by Kaled Aljebur
splunk product badge

Default Version 1.1.1

April 25, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Suricata SOC Investigation is a Splunk app for investigating Suricata IDS and IPS alerts through analyst-focused dashboards, correlation views, anomaly detection, and ATT&CK-aligned context. It helps SOC teams move beyond basic alert counts by providing workflows for triage, attack-story reconstruction, target risk scoring, MITRE mapping, and alert-driven investigation. The app is designed for security analysts who ingest Suricata data into Splunk and need a practical investigation experience built around detection review, prioritization, and response-oriented analysis.