Skip to main content
SpoofSentry Add-on for Splunk app icon

SpoofSentry Add-on for Splunk

Ingest DMARC monitoring, spoofing detection, lookalike domain threats, and takedown events from SpoofSentry with CIM-mapped sourcetypes, pre-built searches, and alerting.Built by Team Netallion
splunk product badge

Default Version 1.0.0

April 9, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported
Ranking

#40 in Email

SpoofSentry Add-on for Splunk ingests and normalizes domain security events from the SpoofSentry DMARC monitoring and domain protection platform. Events are delivered via Splunk HEC and include DMARC authentication failures, spoofing campaign detections, lookalike domain threats, DNS enforcement changes, and automated takedown orchestration lifecycle events. This add-on provides: - Sourcetype definitions for spoofsentry:alert, spoofsentry:cef, and riskreply:event - Automatic JSON field extraction with normalized field aliases (severity, event_type, domain, tenant_id) - CEF (Common Event Format) parsing for legacy SIEM workflows - CIM data model compatibility (Alerts, Email, Intrusion Detection, Change, Web) - 8 pre-built saved searches covering critical threats, DMARC pass rates, spoofing campaigns, lookalike domains, takedown activity, and enforcement changes - 1 pre-built alert for critical threat detection (disabled by default, configurable suppression) - Lookup tables for severity mapping and event type categorization SpoofSentry detects email spoofing, monitors DMARC enforcement, identifies lookalike domains, and orchestrates automated takedowns across Google Web Risk, Netcraft, URLhaus, and registrar abuse channels. This add-on brings those security events into Splunk for centralized analysis, correlation with other security data, and SOC workflow integration.