Skip to main content

COLLECTION

Detection and Response

Collect data across multiple security layers and manage threats quickly. Provide comprehensive protection for your organization.

Network

Track lateral movement or monitor agentless endpoints, like internet of things or operational technology devices.

Vectra Active Enforcement app icon
Not Supported

Vectra Active Enforcement

This app supports investigate and ingest actions on Vectra Active Enforcement platform
Platform: SOAR On-Prem
By
SOAR Community
0 Reviews
ExtraHop app icon
Developer Supported

ExtraHop

This app integrates with your ExtraHop system to gain insight into devices, traffic, and detections in your environment
Platform: SOAR On-Prem, SOAR Cloud
By
SOAR Community
0 Reviews
Palo Alto Networks Firewall app icon
Splunk Supported

Palo Alto Networks Firewall

This app integrates with the Palo Alto Networks Firewall to support containment and investigative actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Vectra Cognito Detect app icon
Developer Supported

Vectra Cognito Detect

Cognito Detect: surface hidden threats from cloud to enterprise The power of AI to detect and prioritize in-progress attacks in real-time - Automate manual processes and consolidate thousands of events and historical context to pinpoint hosts and accounts that pose the biggest threat - High-fidelity visibility into attacker behaviors across all public clouds, private data centers and enterprise environments - Unique context eliminates the endless hunt-and-search for threats and enables immediate action Identify known and unknown threats - Visibility into internal recon and lateral movement attack behaviors - Identify devices and workloads at the center of an attack - Detect intrusions without the limitations of signatures Security analyst in software - Automate a chain of events into a single incident - Instantly triage the highest-risk threats - Behavioral context with every detection https://www.vectra.ai/product/cognito-detect Splunk integration with Vectra solutions sheet: https://content.vectra.ai/rs/748-MCE-447/images/ProductIntegration_2017_Integrating_Cognito_with_Splunk_English.pdf Cognito Detect solutions sheet: https://content.vectra.ai/rs/748-MCE-447/images/ProductCompanyOverview_2019_Cognito_Detect_AI-powered_attacker_detection_English.pdf
Platform: Splunk Enterprise
By
Vectra AI
1 Review
Email Security

See and contain email threats at patient zero before the next user is compromised.

Proofpoint TAP app icon
Not Supported

Proofpoint TAP

This App integrates with Proofpoint to implement ingestion and investigative actions
Platform: SOAR On-Prem
By
SOAR Community
0 Reviews
Mimecast app icon
Splunk Supported

Mimecast

This app integrates with an instance of Mimecast to perform generic, investigative, and containment actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Mimecast  for  Splunk app icon
Developer Supported

Mimecast for Splunk

Cyberattacks can come from many different vectors, but they most commonly arrive via email. By using email to conduct phishing, business email compromise (BEC) attacks, brand impersonation and more, attackers leverage an organization’s weakest security link — its people — to wreak havoc. As a result, email is the No. 1 attack vector for security teams to secure. By integrating Mimecast with Splunk, security teams can leverage advanced threat detection, enhanced investigation, and faster response to increase their overall level of protection through proactive actions that identify at-risk users and devices. Together, the platforms share high-fidelity indicators to help analysts quickly and accurately identify the root cause of an attack and remediate the threat. This helps security teams ward against initial infection and lateral spread that can lead to downtime, ransom demands, lost data, and stolen passwords. Splunk can ingest Mimecast logs, along with other security tools, to obtain complete visibility across environments. Out-of-the-box detection templates created by Mimecast’s team of security experts based on known threats, common attack vectors and suspicious activity reduce detection times to make analysts aware of a threat the moment it occurs. Mimecast regional threat intelligence data can power analytics to generate actionable alerts and incidents, allowing security teams to easily investigate and triage incidents based on the severity and status of detected threats. Additionally, Mimecast provides a Splunk SOAR application as well as a comprehensive Application Programming Interface (API) to make it easy for the platform to be integrated with Splunk’s leading security orchestration, automation, and response (SOAR) for efficient, automated response actions. Installation Guide: https://community.mimecast.com/s/article/api-and-integration-mimecast-for-splunk
Platform: Splunk Enterprise, Splunk Cloud
By
Mimecast Services Ltd
18 Reviews
Proofpoint Email Security Add-On using Remote Syslog app icon
Archived Add-on

Proofpoint Email Security Add-On using Remote Syslog

Customers interested in integrating Proofpoint Protection Server (PPS) logs with Splunk can utilize this custom-built add-on. This technology add-on focuses on normalizing the filter logs based on the Splunk Common Information Model (CIM) for email. By normalizing filtering data produced by PPS to CIM-compliant Email data model, Splunk users can perform search, report or other operations they have built using the Email data model against PPS filtering data without further customizations, which eliminates the need to understand PPS filtering data format.
Platform: Splunk Enterprise
By
Proofpoint Splunk Integrations
16 Reviews
Server/Cloud Workload Monitoring

Keep an eye on containers and serverless functions in your cloud infrastructure.

Microsoft Azure Compute app icon
Splunk Supported

Microsoft Azure Compute

This app implements virtualization actions for Microsoft Azure Virtual Machines
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
AWS EC2 app icon
Splunk Supported

AWS EC2

This app integrates with AWS Elastic Compute Cloud (EC2) to perform virtualization actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Microsoft Azure App for Splunk app icon
Not Supported

Microsoft Azure App for Splunk

The Microsoft Azure App for Splunk contains dashboards for data collected from: Microsoft Azure Add-on for Splunk https://splunkbase.splunk.com/app/3757/ Splunk Add-on for Microsoft Cloud Services https://splunkbase.splunk.com/app/3110/ Splunk Add-on for Microsoft Security https://splunkbase.splunk.com/app/6207 Check out the Help dashboards for ingestion options for Azure data, and onboarding guides for app registrations and permission requirements. Dashboards Include: - Subscriptions - Resources - Virtual Machines - Azure Metrics - Storage Accounts - Security Monitoring - Billing Activity (beta) - Onboarding Guides - MDTI Local Investigation and Articles It is anticipated that future versions may include additional dashboards and data from other Microsoft Azure services. Want to contribute? Help bug fix and suggest enhancements to make this app better! Email: ry@splunk.com
Platform: Splunk Enterprise
By
Splunk Works
5 Reviews
Splunk Add-on for Google Cloud Platform app icon
Splunk Supported

Splunk Add-on for Google Cloud Platform

The Splunk Add-on for Google Cloud Platform allows a Splunk software administrator to collect google cloud platform events, logs, performance metrics and billing data using Google Cloud Platform API. After the Splunk platform indexes the events, you can analyze the data using the prebuilt panels included with the add-on. You can then directly analyze the data or use it as a contextual data feed to correlate with other Google Cloud-related data in the Splunk platform.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
10 Reviews