EN
Request a demo
EN
See all integrations

Splunk

Splunk is a leading SIEM platform that aggregates, indexes, and analyzes machine data from across the enterprise, enabling real-time threat detection, security analytics, and incident investigation through powerful search and correlation capabilities
SIEM & Analytics
11 Analyzers
1 Function
2 External integrations
www.splunk.com GitHub

Analyzers (11)

Enrich observables with intelligence

Splunk Search File Filename v3.0

Execute a savedsearch on a Splunk instance with a file/filename as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: file, filename

Splunk Search Mail Email v3.0

Execute a savedsearch on a Splunk instance with a mail/email as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: mail, email

Splunk Search URL URI Path v3.0

Execute a savedsearch on a Splunk instance with an URL or a URI path as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: url, uri_path

Splunk Search IP v3.0

Execute a savedsearch on a Splunk instance with an IP as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: ip

Splunk Search Other v3.0

Execute a savedsearch on a Splunk instance with an unidentified data as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: other

Splunk Search Registry v3.0

Execute a savedsearch on a Splunk instance with a registry data as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: registry

Splunk Search User v3.0

Execute a savedsearch on a Splunk instance with a user ID as argument

  • Author: LetMeR00t
  • License: AGPL-V3
  • Data Types: other

Splunk Search Mail Subject v3.0

Execute a savedsearch on a Splunk instance with a mail subject as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: mail_subject, mail-subject

Splunk Search Domain FQDN v3.0

Execute a savedsearch on a Splunk instance with a domain or a FQDN as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: domain, fqdn

Splunk Search Hash v3.0

Execute a savedsearch on a Splunk instance with a hash as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: hash

Splunk Search User Agent v3.0

Execute a savedsearch on a Splunk instance with a user agent as argument

  • Author: Unit777, LetMeR00t
  • License: AGPL-V3
  • Data Types: user-agent

Functions (1)

Automate TheHive actions or ingest alerts

createAlertFromSplunk v1.0.0

This function creates a TheHive Alert based on an input coming from Splunk, and matches the Splunk fields to TheHive fields. In Splunk, you'll need to configure the webhook URL to point to the TheHive function URL


External Integrations (2)

External integrations that connect Splunk with TheHive

TheHive/Cortex Technical Add-on

Bidirectional integration add-on that pulls case and alert events from TheHive, retrieves Cortex job information, and enables creating alerts/cases and executing functions in TheHive directly from Splunk searches and dashboards

  • Type: technical-addon

TheHive SOAR Connector

Official Splunk SOAR connector with 16 actions for case management, task operations, observable handling, and TTP tracking to automate incident response workflows between Splunk and TheHive

  • Type: soar-connector
CrowdStrike Falcon
VirusTotal
Microsoft Defender for Endpoint
Microsoft Entra ID
Microsoft Sentinel
MISP
Google Threat Intelligence
Recorded Future
Microsoft Defender for Office 365
Proofpoint
Shodan
Slack
AbuseIPDB
Cloudflare
URLScan.io
URLhaus
ONYPHE
YARA
CAPA
Telegram
Apache Kafka
Mattermost
Microsoft Teams
Redis
Airtable
Autofocus
AWS Lambda
AWX
Axur
BackscatterIO
BinalyzeAIR
Censys
ChainAbuse
CheckPhish
CheckPoint
Check Point HEC
Cisco Duo
CiscoUmbrella
CISMCAP
ClamAV
Cluster25
ClusterHawk
Crtsh
Cuckoo Sandbox
CyberChef
Cyberprotect
Cylance
DNS-RPZ
DNSDB
DNSdumpster
DNSLookingglass
DNSSinkhole
DomainTools
DShield
EchoTrail
EclecticIQ
EmergingThreats
EmlParser
FileInfo
FireHOLBlocklists
FoxIO
Gatewatcher CTI
Gmail
GoogleDNS
GRR Rapid Response
HarfangLab
Hashdd
Inoitsu
IntezerCommunity
Investigate
IP-API
IPVoid
isMalicious
IVRE
JAMFProtect
JIRA
Jupyter
KnowBe4
LdapQuery
Lookyloo
LupovisProwl
Mailer
MailIncidentStatus
Malpedia
MalwareClustering
Malwares
MetaDefender
Microsoft Exchange Online
MsgParser
NERD
Nessus
Netcraft
NSRL
Okta
ONYPHEActiveScan
OpenCTI
OpenCVE
OrionMalware
OVHcloud
PassiveTotal
Patrowl
PDFPreview
PhishingInitiative
Pulsedive
QrDecode
Redmine
Robtex
RT4
SecurityTrails
SendGrid
SentinelOne
SinkDB
SophosIntelix
SpamAssassin
SpamhausDBL
StamusNetworks
StopForumSpam
ThreatGrid
ThreatMiner
ThreatResponse
Thunderstorm
TorBlutmagie
TorProject
Triage
UnshortenLink
urlDNA.io
Valhalla
ValidateObservable
Verifalia
VMRay
Vulners
Watcher
Wazuh
WOT
Yeti
ZEROFOX
Zscaler
Abuse Finder
AIL Onion-Lookup
AlienVault OTX
ANY.RUN
CERT.AT pDNS
CIRCL Hash Lookup
CIRCL Passive DNS
CIRCL Passive SSL
CIRCL Vulnerability-Lookup
Cisco Secure Endpoint (Formerly AMP for Endpoints)
CrowdSec
Domain Mail SPF DMARC
DomainTools Iris
Elasticsearch
EmailRep
FireEye iSIGHT
Forcepoint WebsensePing
Google Safe Browsing
Google Vision API
GreyNoise
Have I Been Pwned
Hunter.io
Hybrid Analysis
IBM QRadar
IBM X-Force
IPinfo
Joe Sandbox
Kaspersky TIP
Maltiverse
MalwareBazaar
Malware Hash Registry (MHR)
MaxMind
MISP Warning Lists
Mnemonic Passive DNS
n8n
PAN Cortex XDR
PAN Cortex XSOAR
PAN Next Generation Firewall
PAN WildFire
PhishTank
Rapid7 InsightConnect
SEKOIA Intelligence Center
Shuffle
ThreatConnect
ThreatQ
Tines
Velociraptor
VirusShare
Bee-come Part of TheHive!
Hundreds of teams all over the world rely on our platform to manage security incidents more efficiently than ever.
Put us to the test today: