August 20, 2026
Mondoo App for Splunk Enterprise
Six prebuilt dashboards for Mondoo data in Splunk: assets, vulnerabilities, policy checks, queries, audit activity and indexing health, plus saved searches and reusable macros. Requires the Mondoo Technology Add-on (TA-mondoo) for data collection.Built by Mondoo IncSplunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3
Log in to rate this app
Mondoo (mondoo_app) provides ready-made dashboards for Mondoo security and compliance data indexed in Splunk. THE PROBLEM Once Mondoo findings are in Splunk, the raw data answers questions only if you already know how to ask. Which assets carry critical CVEs? What failed a policy check this week, and how bad is it? Which assets stopped reporting? Is any of this data actually arriving? Every team ends up rebuilding the same handful of searches and dashboards before they get value from the integration. This app ships them, so the data is useful on day one instead of after a week of SPL. WHAT YOU GET Six dashboards, reached from the app's navigation bar: Assets - inventory with risk and vulnerability scores, platform and space breakdowns, and score trends over time. Vulnerabilities - CVE findings with severity, CVSS score and affected assets. Checks - policy check results by status and severity, with drilldown by asset. Queries - query result coverage and error analysis. Audit - activity in your Mondoo space over time, by user, action and resource. Data Information - indexing health: events by sourcetype, license usage, per-host counts and input intervals. Use this one first to confirm data is landing. SAVED SEARCHES Five searches ship with the app, all disabled by default so nothing starts running scheduled work on install. Enable the ones you want: Critical open vulnerabilities by asset Stale assets (not seen in 7d) Failed checks by severity Audit activity in last 24h New critical CVE finding (an alert, on a 15-minute schedule when enabled) BUILT TO BE EDITED Every dashboard resolves the index through a single macro, mondoo_index, which defaults to index=mondoo. Point the whole app at a different index by editing one line. Further macros are provided as building blocks for your own searches: mondoo_assets, mondoo_vulns, mondoo_advisories, mondoo_checks, mondoo_audit, mondoo_agents, plus severity filters for critical, high-and-above and medium-and-above, and mondoo_active_assets. REQUIREMENTS Splunk Enterprise 9.3 or later. Verified on Splunk 9.3 and 10.2. This app contains dashboards only. It collects nothing on its own and requires the Mondoo Technology Add-on (TA-mondoo) to be collecting data into Splunk. Install this app on your search heads; install the add-on in exactly one place. Licensed Apache-2.0. Source and issue tracker: https://github.com/mondoohq/splunk-app
Log in to report this app listing.