Enricher - Splunk sightings#
Note
This article describes how to configure a particular enrichment source. To see how to configure enrichers in general, see Configure enrichers.
Specifications |
|
---|---|
Enricher name |
Splunk sightings |
Input |
Domain, email, hashes (hash-md5, hash-sha1, hash-sha256, and hash-sha512), host, IP addresses (ipv4 and ipv6), and uri. |
Output |
Creates sightings for matching input observables, based on the search result items retrieved in the specified Splunk instance. |
API endpoint |
|
Description |
The Splunk sightings enricher searches the indices in the specified Splunk instance. Matching data is extracted and saved to the platform as sightings. |
Configure the Splunk sightings enricher parameters#
Select the enricher from the displayed list.
Edit the enricher by selecting from the top right More > Edit.
In the Edit enricher panel, fill out these fields:
Note
Required fields are marked with an asterisk (*).
Splunk URL *
Enter the API URL for your Splunk instance.
This is usually
https://<splunk_server_url>:8089
.Username *
Enter your Splunk username.
Api key *
Enter your Splunk user password.
Search results limit *
Enter the maximum number of search results the enricher retrieves per enrichment.
Select Save.
Additional information#
Search result matches generate sightings that are saved to the platform.
Each sighting includes the following information:
A unique ID.
A URL pointing to the Splunk instance data source.
A URL with the query that retrieved the data.
Details about the sighted observable.
For example, a Splunk index reference, the source log the data was found in, a timestamp, and any raw response data, if available.