Nucleus User Logs Technology Add-on app icon

Nucleus User Logs Technology Add-on

Ingest Nucleus Security audit logs into Splunk for security monitoring, compliance auditing, and user activity analysis. This Technology Add-on provides automated REST API polling with intelligent deduplication and pre-built field extractions for login events, logouts, and role modifications.

Built by
splunk product badge

Latest Version 1.0.7
April 18, 2026
Compatibility
Splunk Enterprise, Splunk Cloud
Platform Version: 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0, 8.2, 8.1, 8.0
CIM Version: 8.x, 6.x, 5.x, 4.x
Rating

0

(0)

Log in to rate this app
Support
Nucleus User Logs Technology Add-on support icon
Developer Supported addon
The Nucleus User Logs Technology Add-on (TA-nucleus-logs) enables seamless ingestion of audit logs from the Nucleus Security platform into Splunk Enterprise. Problem Addressed: Organizations using Nucleus Security need to aggregate and analyze user activity, authentication events, and role modifications for security monitoring, compliance auditing, and incident response. Without this integration, security teams must manually access the Nucleus platform to review audit logs, making it difficult to correlate Nucleus user activity with other security events across their environment. Solution Provided: + Automated Data Collection: Continuously polls the Nucleus Security REST API (/nucleus/api/logs endpoint) to retrieve audit logs at configurable intervals + Intelligent Deduplication: Uses checkpoint-based tracking with SHA1 hashing to prevent duplicate events while ensuring no data loss + Pre-configured Field Extractions: Automatically extracts key fields from audit logs including usernames, actions (login, logout, role modifications), outcomes, browser information, and organizational IDs + CIM Compatibility: Normalizes data with consistent field naming (nucleus.user, nucleus.action, nucleus.outcome) to facilitate integration with Splunk Enterprise Security and other analytics apps + Flexible Deployment: Supports multiple Nucleus instances through separate input configurations Use Cases: + Security monitoring and threat detection (failed logins, unusual access patterns) + Compliance reporting (user access auditing, privileged user tracking) + Incident investigation (correlating Nucleus user activity with security events) + User behavior analytics across hybrid environments

Categories

Information, SIEM

Created By

David Page

Type

addon

Downloads

15

Resources

Log in to report this app listing