Skip to main content
TA_Cisodium app icon

TA_Cisodium

Collects incidents, vulnerabilities, risks, assets, security controls, and audit logs from Cisodium tenants and maps them to CIM domains for security analytics.Built by Yaroslav Duzhyk
splunk product badge

Default Version 1.0.1

September 24, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3

CIM Version: 8.x

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The Cisodium Add-on collects security management data from a Cisodium information security management platform via HTTPS API. The add-on retrieves incidents, vulnerabilities, risks, assets, security controls, and audit logs from a configured Cisodium tenant and indexes them in Splunk as JSON events. Each event represents a record's full state at the time of collection, capturing create, change, and deletion operations to maintain both current and historical views of the security posture. The add-on maps collected data to five Common Information Model domains: Ticket Management for incidents, Vulnerabilities for vulnerability records, Inventory for asset data, Authentication for audit logs, and Change for control and risk modifications. Field extractions and CIM-compliant mappings enable the data to integrate with Splunk Enterprise Security and other analytics applications. The add-on includes a workflow action that allows analysts to open a Cisodium record directly from Splunk search results, and provides dashboards for monitoring collection health and configuring inputs.