Skip to main content

Get more out of Splunk with applications

Trending Apps on Splunkbase

Splunk Enterprise Security app icon
Splunk Supported

Splunk Enterprise Security

Splunk Enterprise Security (ES) solves a wide range of security analytics and operations use cases including continuous security monitoring, advanced threat detection, compliance, incident investigation, forensics and incident response. Splunk ES delivers an end-to-end view of organizations’ security postures with flexible investigations, unmatched performance, and the most flexible deployment options offered in the cloud, on-premises or hybrid deployment models. Splunk ES enables you to: - Conquer alert fatigue with high-fidelity Risk-Based Alerting. - Bring visibility across your hybrid environment with multicloud security monitoring. - Conduct flexible investigations for effective threat hunting across security, IT and DevOps data sources. Splunk ES is a premium security solution requiring a paid license.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
230 Reviews
Splunk MCP Server app icon
Splunk Supported

Splunk MCP Server

MCP Server for Splunk Platform The Model Context Protocol (MCP) is an open standard and framework that enables seamless, secure, and standardized two-way communication between AI applications (like large language models) and external data sources or tools. It acts as a universal adapter allowing AI systems to access, execute, and integrate functionalities from diverse systems through a common protocol, simplifying data sharing and tool interoperability without custom coding for each integration. Splunk's Model Context Protocol (MCP) server leverages this to provide a standardized, secure, and scalable interface to connect AI assistants, agents, and other intelligent systems with data in the Splunk platform for both Enterprise & Cloud customers in beta. 🔑 Key Features - Universal Connectivity Seamlessly connects AI agents and tools to Splunk data resources in a secure and efficient manner. - Enterprise-Grade Security Includes built-in authentication, authorization, and Role-Based Access Control (RBAC). - Rapid Deployment Offers a plug-and-play solution, eliminating the need for custom integrations. ⚙️ Core Capabilities - Explore the Data Navigate and interact with Splunk data effortlessly. - Discover Knowledge Objects Identify and access relevant saved searches, lookups, and other knowledge assets. - Execute Searches Run powerful Splunk queries to extract insights and drive intelligent workflows. - Leverage AI capabilities from Splunk’s AI Assistant for SPL & MLTK SPL search generation from natural language, search optimization, search explanation, retrieve MLTK models and algorithms.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
15 Reviews
Splunk Add-on for Microsoft Windows app icon
Splunk Supported

Splunk Add-on for Microsoft Windows

*** Important: Read upgrade instructions and test add-on update before deploying to production *** The Splunk Add-on for Windows 5.0.0 introduced breaking changes. If you are upgrading from a version of the Splunk Add-on for Windows that is earlier than 5.0.0, you must follow the documented upgrade instructions to avoid data loss. A best practice is to test the upgraded version in a non-production environment before deploying to production. Neither the Splunk Add-on for Windows DNS version 1.0.1 nor the Splunk Add-on for Windows Active Directory version 1.0.0 is supported when installed alongside the Splunk Add-on for Windows version 6.0.0. The Splunk Add-on for Windows version 6.0.0 includes the Splunk Add-on for Windows DNS and the Splunk Add-on for Microsoft Active Directory. The Splunk for Microsoft Windows add-on includes predefined inputs to collect data from Windows systems and maps to normalize the data to the Common Information Model.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
48 Reviews
Splunk MCP Server app icon
Splunk Supported

Splunk MCP Server

MCP Server for Splunk Platform The Model Context Protocol (MCP) is an open standard and framework that enables seamless, secure, and standardized two-way communication between AI applications (like large language models) and external data sources or tools. It acts as a universal adapter allowing AI systems to access, execute, and integrate functionalities from diverse systems through a common protocol, simplifying data sharing and tool interoperability without custom coding for each integration. Splunk's Model Context Protocol (MCP) server leverages this to provide a standardized, secure, and scalable interface to connect AI assistants, agents, and other intelligent systems with data in the Splunk platform for both Enterprise & Cloud customers in beta. 🔑 Key Features - Universal Connectivity Seamlessly connects AI agents and tools to Splunk data resources in a secure and efficient manner. - Enterprise-Grade Security Includes built-in authentication, authorization, and Role-Based Access Control (RBAC). - Rapid Deployment Offers a plug-and-play solution, eliminating the need for custom integrations. ⚙️ Core Capabilities - Explore the Data Navigate and interact with Splunk data effortlessly. - Discover Knowledge Objects Identify and access relevant saved searches, lookups, and other knowledge assets. - Execute Searches Run powerful Splunk queries to extract insights and drive intelligent workflows. - Leverage AI capabilities from Splunk’s AI Assistant for SPL & MLTK SPL search generation from natural language, search optimization, search explanation, retrieve MLTK models and algorithms.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
15 Reviews
Splunk Add-on for Amazon Web Services (AWS) app icon
Splunk Supported

Splunk Add-on for Amazon Web Services (AWS)

The Splunk Add-on for AWS, from version 7.0.0 and above, includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This allows you to configure the Splunk Add-on for AWS to ingest data across all AWS data sources, facilitating the integration of AWS data into your Splunk platform deployment. If you use both the Splunk Add-on for Amazon Security Lake as well as the Splunk Add-on for AWS on the same Splunk instance, then you must uninstall the Splunk Add-on for Amazon Security Lake before upgrading the Splunk Add-on for AWS to version 7.0.0 or later in order to avoid any data duplication and discrepancy issues. __________________________________________________________________________________________________________ Ingesting data from AWS to Splunk Cloud? Have you tried the new Splunk Data Manager yet? Data Manager makes AWS data ingestion simpler, more automated and centrally managed for you, while co-existing with AWS and/or Kinesis TAs. Read our blog post to learn more about Data Manager and it’s availability on your Splunk Cloud instance: https://splk.it/3e9F863 __________________________________________________________________________________________________________ The Splunk Add-on for Amazon Web Services allows a Splunk software administrator to collect: * Configuration snapshots, configuration changes, and historical configuration data from the AWS Config service. * Metadata for your AWS EC2 instances, reserved instances, and EBS snapshots. * Compliance details, compliance summary, and evaluation status of your AWS Config Rules. * Assessment Runs and Findings data from the Amazon Inspector service. * Management and change events from the AWS CloudTrail service. * VPC flow logs and other logs from the CloudWatch Logs service. * Performance and billing metrics from the AWS CloudWatch service. * Billing reports that you have configured in AWS. * S3, CloudFront, and ELB access logs. * Generic data from your S3 buckets. * Generic data from your Kinesis streams. * Generic data from SQS. * Security events from Amazon Security Lake This add-on provides modular inputs and CIM-compatible knowledge to use with other apps, such as the Splunk App for AWS, Splunk Enterprise Security and Splunk IT Service Intelligence. Versions 5.0.0 and later of the Splunk Add-on for AWS is compatible only with Splunk Enterprise version 8.0.0 and above.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
32 Reviews
Splunk AI Toolkit app icon
Splunk Supported

Splunk AI Toolkit

The Splunk AI Toolkit delivers new SPL commands, custom visualizations, assistants, and examples to explore a variety of ML concepts. Each assistant includes end-to-end examples with datasets, plus the ability to apply the visualizations and SPL commands to your own data. You can inspect the assistant panels and underlying code to see how it all works. AI Toolkit Quick Reference Guide: https://docs.splunk.com/images/3/3f/Splunk-MLTK-QuickRefGuide-2019-web.pdf Generative AI: With release 5.6, AI Toolkit supports Generative AI, allowing customers to integrate Large Language Models (LLMs) and Time Series Foundational Models directly into their search pipelines. Agentic Capabilities: With release 6.0.0, AI Toolkit introduces Agent Launchpad, enabling customers to create AI agents directly within the app, connect their own MCP servers, Knowledge bases and build agentic workflows. Assistants: * Predict Numeric Fields (Linear Regression): e.g. predict median house values. * Predict Categorical Fields (Logistic Regression): e.g. predict customer churn. * Detect Numeric Outliers (distribution statistics): e.g. detect outliers in IT Ops data. * Detect Categorical Outliers (probabilistic measures): e.g. detect outliers in diabetes patient records. * Forecast Time Series: e.g. forecast data center growth and capacity planning. * Cluster Numeric Events: e.g. cluster business anomalies to reduce noise. Smart Assistants (new assistants with revamped UI and better ml pipeline/experiment management): * Smart Forecasting Assistant:: e.g. forecasting app logons with special days. * Smart Outlier Detection Assistant: e.g. find anomalies in supermarket purchases. * Smart Clustering Assistant: e.g. cluster houses by property descriptions. * Smart Prediction Assistant: e.g. predict vulnerabilities in firewall data.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
41 Reviews
Cisco Security Cloud app icon
Cisco Supported

Cisco Security Cloud

The Cisco Security Cloud application offers seamless integration for connecting your Cisco devices with Splunk. It features a modular UX input design, built-in health checks, and constant monitoring to ensure operational integrity. Product(s) Enabled: Cisco AI Defense Cisco Duo Cisco Email Threat Defense (ETD) Cisco Endpoint Visibility Module (EVM) CIM Mappings (Beta) Cisco Identity Intelligence (CII) Cisco Multicloud Defense Cisco NVM Cisco Secure Endpoint Cisco Secure Firewall (FTD/eStreamer/ASA) Cisco Secure Workload Cisco Isovalent Cisco Isovalent Edge Processor **Alpha Cisco Secure Malware Analytics (SMA) Cisco Secure Network Analytics (SNA) Cisco Vulnerability Intelligence Cisco XDR (Incident Import & Promote to ES Notable) Here’s the revised version with the sourcetype list and stronger 3.x transition language. **MAJOR VERSION CHANGE: CiscoSecurityCloud 4.0.0 Release Notes** CiscoSecurityCloud 4.0.0 introduces expanded Cisco Secure Firewall / FTD syslog and Advanced Logging support, with improved parsing, event routing, CIM/data model alignment, dashboard visibility, and ingestion reliability. This release adds a new FTD sourcetype routing model that separates FTD events by event family instead of keeping all events under a single generic `cisco:ftd:syslog` sourcetype. This improves field extraction accuracy, dashboard filtering, data model mapping, and long-term supportability for FTD syslog and Advanced Logging data. Because this changes how FTD events are categorized, **4.0.0 may be a breaking change for customers with custom Splunk content**. Content that may require review includes: - Saved searches, alerts, reports, and dashboards that filter only on `sourcetype="cisco:ftd:syslog"` - Custom macros, eventtypes, tags, and CIM/data model constraints - Custom props/transforms or routing assumptions for FTD syslog - Data model acceleration searches scoped to the previous FTD sourcetype - External integrations or correlation searches that expect all FTD events in one sourcetype Customers should update broad FTD searches from "cisco:ftd:syslog" to cisco:ftd:intrusion cisco:ftd:connection cisco:ftd:connection:security cisco:ftd:file cisco:ftd:malware cisco:ftd:discovery cisco:ftd:useractivity cisco:ftd:correlation cisco:ftd:intrusionpacket cisco:ftd:adv:http cisco:ftd:adv:ftp cisco:ftd:adv:conn cisco:ftd:adv:dns cisco:ftd:adv:weird cisco:ftd:adv:notice CiscoSecurityCloud 4.0.0 is intended for customers who want the new FTD Advanced Logging model and are ready to validate custom content against the expanded sourcetypes. To ease the transition, the CiscoSecurityCloud 3.x branch will be actively maintained and should remain the recommended stable branch for customers who require the existing FTD sourcetype behavior. Customers can continue using 3.x while they assess 4.0.0, update custom SPL, and validate dashboards, alerts, and data model acceleration.
Platform: Splunk Enterprise, Splunk Cloud
By
Cisco Systems, Inc.
14 Reviews

New Splunk Built and Supported Apps

See All
Splunk Add-on for Salesforce app icon
Splunk Supported

Splunk Add-on for Salesforce

*** Important: Read upgrade instructions and test your add-on update before deploying to production *** Version 2.0.0 of the Splunk Add-on for Salesforce introduces breaking changes. To avoid data loss or data duplication, follow the documented upgrade instructions in detail. If your are upgrading an earlier version of the Splunk Add-on for Salesforce, a best practice is to test your update in a non-production environment before deploying to production. The Splunk Add-on for Salesforce allows a Splunk software administrator to collect different types of data from Salesforce using REST APIs. The data includes: * Event log file data, https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/using_resources_event_log_files.htm. * Output of Salesforce object queries (SOQL). This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security, the Splunk App for PCI Compliance, and Splunk IT Service Intelligence.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
11 Reviews
Splunk Add-on for ServiceNow app icon
Splunk Supported

Splunk Add-on for ServiceNow

The Splunk Add-on for ServiceNow allows a Splunk software administrator to collect data from ServiceNow and create incidents and events in ServiceNow. The add-on collects incident, event, change, user, user group, location, and CMDB CI information from ServiceNow via ServiceNow REST APIs. The add-on also provides workflow actions that allow users to link directly from events in the Splunk platform search results to relevant ServiceNow incidents, events, and Knowledge Base articles. The Splunk Add-on for ServiceNow allows Splunk software administrators to use custom commands, alert actions, and scripts to create new incidents and events in your ServiceNow instance, as well as update the incidents created from the Splunk platform. This add-on provides the inputs and CIM-compatible knowledge to use with other Splunk apps, such as Splunk Enterprise Security and the Splunk App for PCI Compliance.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
16 Reviews
Splunk AI Toolkit app icon
Splunk Supported

Splunk AI Toolkit

The Splunk AI Toolkit delivers new SPL commands, custom visualizations, assistants, and examples to explore a variety of ML concepts. Each assistant includes end-to-end examples with datasets, plus the ability to apply the visualizations and SPL commands to your own data. You can inspect the assistant panels and underlying code to see how it all works. AI Toolkit Quick Reference Guide: https://docs.splunk.com/images/3/3f/Splunk-MLTK-QuickRefGuide-2019-web.pdf Generative AI: With release 5.6, AI Toolkit supports Generative AI, allowing customers to integrate Large Language Models (LLMs) and Time Series Foundational Models directly into their search pipelines. Agentic Capabilities: With release 6.0.0, AI Toolkit introduces Agent Launchpad, enabling customers to create AI agents directly within the app, connect their own MCP servers, Knowledge bases and build agentic workflows. Assistants: * Predict Numeric Fields (Linear Regression): e.g. predict median house values. * Predict Categorical Fields (Logistic Regression): e.g. predict customer churn. * Detect Numeric Outliers (distribution statistics): e.g. detect outliers in IT Ops data. * Detect Categorical Outliers (probabilistic measures): e.g. detect outliers in diabetes patient records. * Forecast Time Series: e.g. forecast data center growth and capacity planning. * Cluster Numeric Events: e.g. cluster business anomalies to reduce noise. Smart Assistants (new assistants with revamped UI and better ml pipeline/experiment management): * Smart Forecasting Assistant:: e.g. forecasting app logons with special days. * Smart Outlier Detection Assistant: e.g. find anomalies in supermarket purchases. * Smart Clustering Assistant: e.g. cluster houses by property descriptions. * Smart Prediction Assistant: e.g. predict vulnerabilities in firewall data.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
41 Reviews
Splunk AI Toolkit app icon
Splunk Supported

Splunk AI Toolkit

The Splunk AI Toolkit delivers new SPL commands, custom visualizations, assistants, and examples to explore a variety of ML concepts. Each assistant includes end-to-end examples with datasets, plus the ability to apply the visualizations and SPL commands to your own data. You can inspect the assistant panels and underlying code to see how it all works. AI Toolkit Quick Reference Guide: https://docs.splunk.com/images/3/3f/Splunk-MLTK-QuickRefGuide-2019-web.pdf Generative AI: With release 5.6, AI Toolkit supports Generative AI, allowing customers to integrate Large Language Models (LLMs) and Time Series Foundational Models directly into their search pipelines. Agentic Capabilities: With release 6.0.0, AI Toolkit introduces Agent Launchpad, enabling customers to create AI agents directly within the app, connect their own MCP servers, Knowledge bases and build agentic workflows. Assistants: * Predict Numeric Fields (Linear Regression): e.g. predict median house values. * Predict Categorical Fields (Logistic Regression): e.g. predict customer churn. * Detect Numeric Outliers (distribution statistics): e.g. detect outliers in IT Ops data. * Detect Categorical Outliers (probabilistic measures): e.g. detect outliers in diabetes patient records. * Forecast Time Series: e.g. forecast data center growth and capacity planning. * Cluster Numeric Events: e.g. cluster business anomalies to reduce noise. Smart Assistants (new assistants with revamped UI and better ml pipeline/experiment management): * Smart Forecasting Assistant:: e.g. forecasting app logons with special days. * Smart Outlier Detection Assistant: e.g. find anomalies in supermarket purchases. * Smart Clustering Assistant: e.g. cluster houses by property descriptions. * Smart Prediction Assistant: e.g. predict vulnerabilities in firewall data.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
41 Reviews

Splunkbase Collections

See All

Getting Started with AI

9 solutions

These Machine Learning and AI powered apps and assistants give you the power of Machine Learning for common use cases with just a couple of clicks.

Collection icon

Pipeline Analytics for DevOps

13 solutions

Create visibility across your software development lifecycle

Collection icon

Detection and Response

31 solutions

Collect data across multiple security layers and manage threats quickly. Provide comprehensive protection for your organization.

Collection icon

Getting Started with Security

15 solutions

These are the best apps to help you get started with security.

Collection icon

Most popular Splunk Cloud Apps

See All
Splunk Add-on for Amazon Web Services (AWS) app icon
Splunk Supported

Splunk Add-on for Amazon Web Services (AWS)

The Splunk Add-on for AWS, from version 7.0.0 and above, includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This allows you to configure the Splunk Add-on for AWS to ingest data across all AWS data sources, facilitating the integration of AWS data into your Splunk platform deployment. If you use both the Splunk Add-on for Amazon Security Lake as well as the Splunk Add-on for AWS on the same Splunk instance, then you must uninstall the Splunk Add-on for Amazon Security Lake before upgrading the Splunk Add-on for AWS to version 7.0.0 or later in order to avoid any data duplication and discrepancy issues. __________________________________________________________________________________________________________ Ingesting data from AWS to Splunk Cloud? Have you tried the new Splunk Data Manager yet? Data Manager makes AWS data ingestion simpler, more automated and centrally managed for you, while co-existing with AWS and/or Kinesis TAs. Read our blog post to learn more about Data Manager and it’s availability on your Splunk Cloud instance: https://splk.it/3e9F863 __________________________________________________________________________________________________________ The Splunk Add-on for Amazon Web Services allows a Splunk software administrator to collect: * Configuration snapshots, configuration changes, and historical configuration data from the AWS Config service. * Metadata for your AWS EC2 instances, reserved instances, and EBS snapshots. * Compliance details, compliance summary, and evaluation status of your AWS Config Rules. * Assessment Runs and Findings data from the Amazon Inspector service. * Management and change events from the AWS CloudTrail service. * VPC flow logs and other logs from the CloudWatch Logs service. * Performance and billing metrics from the AWS CloudWatch service. * Billing reports that you have configured in AWS. * S3, CloudFront, and ELB access logs. * Generic data from your S3 buckets. * Generic data from your Kinesis streams. * Generic data from SQS. * Security events from Amazon Security Lake This add-on provides modular inputs and CIM-compatible knowledge to use with other apps, such as the Splunk App for AWS, Splunk Enterprise Security and Splunk IT Service Intelligence. Versions 5.0.0 and later of the Splunk Add-on for AWS is compatible only with Splunk Enterprise version 8.0.0 and above.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
32 Reviews
Splunk Add-on for Microsoft Windows app icon
Splunk Supported

Splunk Add-on for Microsoft Windows

*** Important: Read upgrade instructions and test add-on update before deploying to production *** The Splunk Add-on for Windows 5.0.0 introduced breaking changes. If you are upgrading from a version of the Splunk Add-on for Windows that is earlier than 5.0.0, you must follow the documented upgrade instructions to avoid data loss. A best practice is to test the upgraded version in a non-production environment before deploying to production. Neither the Splunk Add-on for Windows DNS version 1.0.1 nor the Splunk Add-on for Windows Active Directory version 1.0.0 is supported when installed alongside the Splunk Add-on for Windows version 6.0.0. The Splunk Add-on for Windows version 6.0.0 includes the Splunk Add-on for Windows DNS and the Splunk Add-on for Microsoft Active Directory. The Splunk for Microsoft Windows add-on includes predefined inputs to collect data from Windows systems and maps to normalize the data to the Common Information Model.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
48 Reviews
Splunk Add-on for Amazon Web Services (AWS) app icon
Splunk Supported

Splunk Add-on for Amazon Web Services (AWS)

The Splunk Add-on for AWS, from version 7.0.0 and above, includes a merge of all the capabilities of the Splunk Add-on for Amazon Security Lake. This allows you to configure the Splunk Add-on for AWS to ingest data across all AWS data sources, facilitating the integration of AWS data into your Splunk platform deployment. If you use both the Splunk Add-on for Amazon Security Lake as well as the Splunk Add-on for AWS on the same Splunk instance, then you must uninstall the Splunk Add-on for Amazon Security Lake before upgrading the Splunk Add-on for AWS to version 7.0.0 or later in order to avoid any data duplication and discrepancy issues. __________________________________________________________________________________________________________ Ingesting data from AWS to Splunk Cloud? Have you tried the new Splunk Data Manager yet? Data Manager makes AWS data ingestion simpler, more automated and centrally managed for you, while co-existing with AWS and/or Kinesis TAs. Read our blog post to learn more about Data Manager and it’s availability on your Splunk Cloud instance: https://splk.it/3e9F863 __________________________________________________________________________________________________________ The Splunk Add-on for Amazon Web Services allows a Splunk software administrator to collect: * Configuration snapshots, configuration changes, and historical configuration data from the AWS Config service. * Metadata for your AWS EC2 instances, reserved instances, and EBS snapshots. * Compliance details, compliance summary, and evaluation status of your AWS Config Rules. * Assessment Runs and Findings data from the Amazon Inspector service. * Management and change events from the AWS CloudTrail service. * VPC flow logs and other logs from the CloudWatch Logs service. * Performance and billing metrics from the AWS CloudWatch service. * Billing reports that you have configured in AWS. * S3, CloudFront, and ELB access logs. * Generic data from your S3 buckets. * Generic data from your Kinesis streams. * Generic data from SQS. * Security events from Amazon Security Lake This add-on provides modular inputs and CIM-compatible knowledge to use with other apps, such as the Splunk App for AWS, Splunk Enterprise Security and Splunk IT Service Intelligence. Versions 5.0.0 and later of the Splunk Add-on for AWS is compatible only with Splunk Enterprise version 8.0.0 and above.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
32 Reviews
Splunk AI Toolkit app icon
Splunk Supported

Splunk AI Toolkit

The Splunk AI Toolkit delivers new SPL commands, custom visualizations, assistants, and examples to explore a variety of ML concepts. Each assistant includes end-to-end examples with datasets, plus the ability to apply the visualizations and SPL commands to your own data. You can inspect the assistant panels and underlying code to see how it all works. AI Toolkit Quick Reference Guide: https://docs.splunk.com/images/3/3f/Splunk-MLTK-QuickRefGuide-2019-web.pdf Generative AI: With release 5.6, AI Toolkit supports Generative AI, allowing customers to integrate Large Language Models (LLMs) and Time Series Foundational Models directly into their search pipelines. Agentic Capabilities: With release 6.0.0, AI Toolkit introduces Agent Launchpad, enabling customers to create AI agents directly within the app, connect their own MCP servers, Knowledge bases and build agentic workflows. Assistants: * Predict Numeric Fields (Linear Regression): e.g. predict median house values. * Predict Categorical Fields (Logistic Regression): e.g. predict customer churn. * Detect Numeric Outliers (distribution statistics): e.g. detect outliers in IT Ops data. * Detect Categorical Outliers (probabilistic measures): e.g. detect outliers in diabetes patient records. * Forecast Time Series: e.g. forecast data center growth and capacity planning. * Cluster Numeric Events: e.g. cluster business anomalies to reduce noise. Smart Assistants (new assistants with revamped UI and better ml pipeline/experiment management): * Smart Forecasting Assistant:: e.g. forecasting app logons with special days. * Smart Outlier Detection Assistant: e.g. find anomalies in supermarket purchases. * Smart Clustering Assistant: e.g. cluster houses by property descriptions. * Smart Prediction Assistant: e.g. predict vulnerabilities in firewall data.
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
41 Reviews
Splunk Security Essentials app icon
Splunk Supported

Splunk Security Essentials

Get started with Splunk for Security with Splunk Security Essentials (SSE). Explore security use cases and discover security content to start address threats and challenges. Security Content Library Find security content for Splunk Cloud and Splunk's SIEM and SOAR offerings and deploy out-of-the-box security detections and analytic stories to enhance your investigations and improve your security posture. Cybersecurity Frameworks Identify gaps in your defenses and take control of your security posture with automatic mapping of data and security detections to MITRE ATT&CK® and Cyber Kill Chain® framework. Data and Content Introspection Gain visibility of the data coming into your environment to add context and telemetry to security events. Enrich your security detections with metadata and tags from the Security Content Library. Security Data Journey Get prescriptive security and data recommendations and establish a data strategy to develop a security maturity roadmap. We have changed the security content delivery endpoint for ESCU to comply with Splunk guidance. This means that if you have SSE version 3.7.1 or lower, the last supported ESCU version is ESCU 4.22.0. In order to get the latest ESCU version, you will need to upgrade SSE to version 3.8.0. Learn more: Download the Product Brief : https://www.splunk.com/pdfs/product-briefs/splunk-security-essentials.pdf Try out Splunk Security Essentials: https://www.splunk.com/en_us/form/splunk-security-essentials-online-demo.html Check out the Documentation site: https://docs.splunk.com/Documentation/SSE
Platform: Splunk Enterprise, Splunk Cloud
By
Splunk LLC
57 Reviews

Most popular SOAR Connectors

See All

Not finding the perfect app? Build it!

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community.

Image