COLLECTION
Detection and Response
Collect data across multiple security layers and manage threats quickly. Provide comprehensive protection for your organization.
Endpoint
Pull in endpoint detections to jump start your detection and response workflows.
Not Supported
Cybereason
This app integrates with the Cybereason platform to perform investigative, contain, and corrective actions on Malop and Malware events
Platform: SOAR On-Prem, SOAR Cloud
By
SOAR Community
0 Reviews
Not Supported
SentinelOne
This app integrates with the SentinelOne Singularity platform to perform prevention, detection, remediation, and forensic endpoint management tasks
Platform: SOAR On-Prem, SOAR Cloud
By
SOAR Community
0 Reviews
Splunk Supported
Carbon Black Response
This app supports executing various endpoint-based investigative and containment actions on Carbon Black Response
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Developer Supported
SentinelOne App For Splunk
The SentinelOne App For Splunk allows a SentinelOne administrator or analyst to interact with the SentinelOne product.
Platform: Splunk Enterprise, Splunk Cloud
By
SentinelOne Singularity
15 Reviews
Network
Track lateral movement or monitor agentless endpoints, like internet of things or operational technology devices.
Not Supported
Vectra Active Enforcement
This app supports investigate and ingest actions on Vectra Active Enforcement platform
Platform: SOAR On-Prem
By
SOAR Community
0 Reviews
Developer Supported
ExtraHop
This app integrates with your ExtraHop system to gain insight into devices, traffic, and detections in your environment
Platform: SOAR On-Prem, SOAR Cloud
By
SOAR Community
0 Reviews
Splunk Supported
Palo Alto Networks Firewall
This app integrates with the Palo Alto Networks Firewall to support containment and investigative actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Developer Supported
Vectra Cognito Detect
Cognito Detect: surface hidden threats from cloud to enterprise
The power of AI to detect and prioritize in-progress attacks in real-time
- Automate manual processes and consolidate thousands of events and historical context to pinpoint hosts and accounts that pose the biggest threat
- High-fidelity visibility into attacker behaviors across all public clouds, private data centers and enterprise environments
- Unique context eliminates the endless hunt-and-search for threats and enables immediate action
Identify known and unknown threats
- Visibility into internal recon and lateral movement attack behaviors
- Identify devices and workloads at the center of an attack
- Detect intrusions without the limitations of signatures
Security analyst in software
- Automate a chain of events into a single incident
- Instantly triage the highest-risk threats
- Behavioral context with every detection
https://www.vectra.ai/product/cognito-detect
Splunk integration with Vectra solutions sheet:
https://content.vectra.ai/rs/748-MCE-447/images/ProductIntegration_2017_Integrating_Cognito_with_Splunk_English.pdf
Cognito Detect solutions sheet:
https://content.vectra.ai/rs/748-MCE-447/images/ProductCompanyOverview_2019_Cognito_Detect_AI-powered_attacker_detection_English.pdf
Platform: Splunk Enterprise
By
Vectra AI
1 Review
Email Security
See and contain email threats at patient zero before the next user is compromised.
Not Supported
Proofpoint TAP
This App integrates with Proofpoint to implement ingestion and investigative actions
Platform: SOAR On-Prem
By
SOAR Community
0 Reviews
Splunk Supported
Mimecast
This app integrates with an instance of Mimecast to perform generic, investigative, and containment actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Developer Supported
Mimecast for Splunk
Cyberattacks can come from many different vectors, but they most commonly arrive via email. By using email to conduct phishing, business email compromise (BEC) attacks, brand impersonation and more, attackers leverage an organization’s weakest security link — its people — to wreak havoc. As a result, email is the No. 1 attack vector for security teams to secure.
By integrating Mimecast with Splunk, security teams can leverage advanced threat detection, enhanced investigation, and faster response to increase their overall level of protection through proactive actions that identify at-risk users and devices. Together, the platforms share high-fidelity indicators to help analysts quickly and accurately identify the root cause of an attack and remediate the threat. This helps security teams ward against initial infection and lateral spread that can lead to downtime, ransom demands, lost data, and stolen passwords.
Splunk can ingest Mimecast logs, along with other security tools, to obtain complete visibility across environments. Out-of-the-box detection templates created by Mimecast’s team of security experts based on known threats, common attack vectors and suspicious activity reduce detection times to make analysts aware of a threat the moment it occurs.
Mimecast regional threat intelligence data can power analytics to generate actionable alerts and incidents, allowing security teams to easily investigate and triage incidents based on the severity and status of detected threats. Additionally, Mimecast provides a Splunk SOAR application as well as a comprehensive Application Programming Interface (API) to make it easy for the platform to be integrated with Splunk’s leading security orchestration, automation, and response (SOAR) for efficient, automated response actions.
Installation Guide: https://community.mimecast.com/s/article/api-and-integration-mimecast-for-splunk
Platform: Splunk Enterprise, Splunk Cloud
By
Mimecast Services Ltd
18 Reviews
Archived Add-on
Proofpoint Email Security Add-On using Remote Syslog
Customers interested in integrating Proofpoint Protection Server (PPS) logs with Splunk can utilize this custom-built add-on. This technology add-on focuses on normalizing the filter logs based on the Splunk Common Information Model (CIM) for email.
By normalizing filtering data produced by PPS to CIM-compliant Email data model, Splunk users can perform search, report or other operations they have built using the Email data model against PPS filtering data without further customizations, which eliminates the need to understand PPS filtering data format.
Platform: Splunk Enterprise
By
Proofpoint Splunk Integrations
16 Reviews
Server/Cloud Workload Monitoring
Keep an eye on containers and serverless functions in your cloud infrastructure.
Splunk Supported
Microsoft Azure Compute
This app implements virtualization actions for Microsoft Azure Virtual Machines
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Splunk Supported
AWS EC2
This app integrates with AWS Elastic Compute Cloud (EC2) to perform virtualization actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Not Supported
Microsoft Azure App for Splunk
The Microsoft Azure App for Splunk contains dashboards for data collected from:
Microsoft Azure Add-on for Splunk
https://splunkbase.splunk.com/app/3757/
Splunk Add-on for Microsoft Cloud Services
https://splunkbase.splunk.com/app/3110/
Splunk Add-on for Microsoft Security
https://splunkbase.splunk.com/app/6207
Check out the Help dashboards for ingestion options for Azure data, and onboarding guides for app registrations and permission requirements.
Dashboards Include:
- Subscriptions
- Resources
- Virtual Machines
- Azure Metrics
- Storage Accounts
- Security Monitoring
- Billing Activity (beta)
- Onboarding Guides
- MDTI Local Investigation and Articles
It is anticipated that future versions may include additional dashboards and data from other Microsoft Azure services.
Want to contribute?
Help bug fix and suggest enhancements to make this app better!
Email: ry@splunk.com
Platform: Splunk Enterprise
By
Splunk Works
5 Reviews
Splunk Supported
Splunk Add-on for Google Cloud Platform
The Splunk Add-on for Google Cloud Platform allows a Splunk software administrator to collect google cloud platform events, logs, performance metrics and billing data using Google Cloud Platform API.
After the Splunk platform indexes the events, you can analyze the data using the prebuilt panels included with the add-on. You can then directly analyze the data or use it as a contextual data feed to correlate with other Google Cloud-related data in the Splunk platform.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
10 Reviews
Identity
Link attacks to users and proactively block attacks from potentially compromised accounts.
Splunk Supported
Okta
This app supports various identity management actions on Okta
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Splunk Supported
Azure AD Graph
Connects to Azure AD Graph REST API services
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Splunk Supported
AWS IAM
This app integrates with Amazon Web Services Identity Access Management (AWS IAM) to support various containment, corrective and investigate actions
Platform: SOAR On-Prem, SOAR Cloud
By
Splunk LLC
0 Reviews
Archived Add-on
Okta Identity Cloud Add-on for Splunk
Using Okta Identity Cloud REST APIs the Okta Identity Cloud Add-on for splunk allows a Splunk® administrator to collect data from the Okta Identity Cloud. The Add-on collects data related to:
• Event log information
• User information
• Group and Group Membership Information
• Application and Application Assignment information
Using Okta Identity Cloud REST APIs this Add-on supports adaptive response actions and custom alerts that enable taking the following actions from Splunk:
• Adding and removing Okta users from groups in Okta
• Performing account lifecycle actions (e.g. suspend, deactivate, expire) on Users in Okta
This Add-on provides inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.
Platform: Splunk Enterprise
By
Okta Inc
14 Reviews