The Anchore Add-on For Splunk collects vulnerability data from Anchore Enterprise APIs and ingests it into Splunk via HTTP Event Collector. The add-on retrieves vulnerability scanner metrics through a modular input that queries Anchore APIs at configurable intervals and indexes the data with the anchore:vulnerabilities sourcetype. It includes a security vulnerability dashboard that displays real-time vulnerability metrics, severity-based alerting, and interactive filtering capabilities. Organizations using Anchore for container image scanning can use this add-on to centralize vulnerability monitoring within their Splunk environment. The add-on supports multi-account Anchore deployments and allows security teams to track vulnerability counts, affected images, and security scores across container registries and repositories.
Categories
Security, Fraud & Compliance, Vulnerability Scanner
Resources
Log in to report this app listing