Skip to main content
DV IOC Enrichment app icon

DV IOC Enrichment

Automated VirusTotal, AbuseIPDB, MISP, and AlienVault OTX enrichment for Splunk ES notable events with caching, quota-aware key rotation, exclusions, and urgency updates.Built by Mustafa YILMAZ
splunk product badge

Default Version 1.2.0

August 23, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0

Rating
5
(3)

Log in to rate this app

Support
Developer Supported

DV IOC Enrichment automates threat intelligence enrichment for Splunk Enterprise Security notable events. The app extracts IP addresses, domains, URLs, and file hashes from configured notable event fields and queries supported intelligence providers, including VirusTotal, AbuseIPDB, MISP, and AlienVault OTX. Provider responses are evaluated against configurable thresholds, and malicious findings can automatically update the notable event urgency, add enrichment evidence as an ES comment, and trigger an email notification. DV IOC Enrichment addresses the operational overhead of manually investigating repeated indicators while preventing unnecessary API usage through configurable caching, exclusion rules, provider-specific quota controls, and multi-key rotation. Each provider operates independently. If one provider becomes unavailable or reaches its quota, enrichment continues through the remaining providers. Temporarily incomplete events can be retried when provider capacity becomes available again. The app includes: - Automatic enrichment of Splunk ES notable events - VirusTotal support for IP, domain, URL, and hash indicators - AbuseIPDB support for public IP reputation - MISP support for IP, domain, URL, and hash attribute matches - AlienVault OTX support for IP, domain, URL, and hash pulse intelligence - Configurable provider-specific thresholds - Multiple API keys with quota-aware rotation - Per-provider request and quota controls - Reusable enrichment cache with configurable TTL - Exact, CIDR, IP range, and domain suffix exclusions - Independent provider fallback and retry handling - Automatic urgency updates and ES comments - Optional email notifications - Operational dashboard with provider evidence drilldown - Read-only application Health Check - Structured internal logging