Splunkbase Apps

This is free to download and install but paid to use.

Threat hunting add-on that is a community that shares IP address and Urls of malicious endpoints and compares those IP to the IP in the spunk index

Video and Instructions

Splunk Addon for Microsoft cloud

Splunk ES Content Update

The Splunk ES Content Update (ESCU) app delivers pre-packaged Security Content. ESCU provides regular Security Content updates to help security practitioners address ongoing time-sensitive threats, attack methods, and other security issues. Security Content consists of tactics,

Last updated