Splunk (v4.3.3)

Fetch events as incidents and search Splunk

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Default data source
SplunkPy
Categories
Analytics & SIEM

Incident fields (31)

Integrations (2)

Layouts (3)

Playbooks (2)

Scripts (9)

README

This content pack runs queries on Splunk servers and fetches events from both Splunk Enterprise Security (ES) and non-ES environments.

What does this pack do?

This pack includes two integrations designed for different Splunk ES versions:

SplunkPy

The primary integration for Splunk ES versions up to 8.1, which automatically fetches notable events from Splunk along with their context data. The integration provides the analyst with comprehensive incident information directly in the XSOAR/XSIAM console.

SplunkPy v2

Designed for Splunk ES version 8.2 and higher, supporting the new Splunk Enterprise Security architecture (Findings and Investigations).

Using the commands in these integrations, you can leverage the Splunk API capabilities, such as:

Note:
When mirroring or fetching incidents between Splunk and Cortex XSOAR, you need to map Splunk users to Cortex XSOAR users.