August 20, 2026
Mondoo Add-On (TA) for Splunk
Ingests security and compliance data from the Mondoo platform into Splunk: vulnerabilities, policy checks, asset inventory, advisories and audit activity. Collects via the Mondoo API on a schedule or from file-based ETL exports, with CIM mappings for the Vulnerabilities, Change, Inventory and Alerts data models.Built by Mondoo IncSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3
Log in to rate this app
Mondoo Log Ingestion (TA-mondoo) brings security and compliance data from the Mondoo platform into Splunk. THE PROBLEM Mondoo continuously assesses your infrastructure for vulnerabilities, misconfigurations and policy violations. That data is valuable, but it lives in a separate console. Security teams end up switching tools to answer basic questions: does this CVE affect a production asset, did a failing control coincide with a change, which hosts drifted out of compliance this week. Correlating Mondoo findings with the logs already in Splunk otherwise means manual exports and spreadsheets. WHAT THIS ADD-ON DOES TA-mondoo collects Mondoo data on a schedule and indexes it in Splunk, so findings sit alongside your existing telemetry and can be searched, alerted on, and built into dashboards and compliance reports. Two collection paths: 1. Mondoo GraphQL API (modular input), polling your Mondoo space on a configurable interval: mondoo:rest:audit - audit trail of actions in your space mondoo:rest:advisory - security advisories mondoo:rest:agent - registered Mondoo agents 2. File-based ETL (file monitor), ingesting JSONL exports from the Mondoo ETL runner, routed to sourcetypes automatically by filename: mondoo:json:asset, :vuln, :check, :control, :package, :query CIM MAPPING Events are tagged and field-aliased for the Splunk Common Information Model, so they populate the Vulnerabilities, Change, Inventory and Alerts data models and work with CIM-based apps and correlation searches. OPERATIONAL DETAIL Checkpointed, resumable pagination, so restarts neither duplicate nor lose events, with a configurable lookback window on first run. Automatic retry with exponential backoff on rate limits and transient errors, honouring Retry-After headers. Outbound HTTPS proxy and custom CA bundle support for restricted networks. Bearer tokens and JWTs are scrubbed from every log line, so diagnostic output is safe to attach to support tickets. Configurable from Splunk Web or directly in inputs.conf. DEPLOYMENT Install on a single instance: a heavy forwarder, or the search head in smaller deployments. The modular input is stateful and writes checkpoint files, so enabling it on more than one search head cluster member produces duplicate events. Requires Splunk Enterprise 9.0 or later and a Mondoo service account. Tested on Splunk 9.x and 10.2. DASHBOARDS The companion app "Mondoo" (mondoo_app) provides prebuilt dashboards for asset inventory, vulnerabilities, policy checks, query coverage and data quality, built on the sourcetypes above. It is optional; the add-on indexes data on its own. Licensed Apache-2.0. Source and issue tracker: https://github.com/mondoohq/splunk-app
Log in to report this app listing.