Skip to main content
Flare Splunk App app icon

Flare Splunk App

Collects cyber threat intelligence from Flare's CTI platform, including ransom leaks, stealer logs, compromised credentials, and dark web activity, with CIM-compliant field extractions and dashboards.Built by Flare Inc
splunk product badge

Default Version 1.0.3

August 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

Flare integrates Splunk with Flare's Threat Intelligence platform to collect cyber threat intelligence events via API. The app ingests ransom leaks, stealer logs, compromised credentials, lookalike domains, and dark web activity, enabling security teams to monitor external threats targeting their organization. Events are normalized to the Common Information Model (CIM) and mapped to the Alerts, Malware, Network Resolution (DNS), and Threat Intelligence data models. The app includes dashboards for threat visualization, saved searches for reporting on leaked credentials and severity distributions, and configuration options for filtering events by tenant, severity, and source type. Security operations teams can use Flare to assess risk posture, track credential exposure, and respond to emerging threats discovered through dark web monitoring and external attack surface analysis.