icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Illumio Technology Add-On for Splunk
SHA256 checksum (illumio-technology-add-on-for-splunk_324.tgz) 07f7590f4113a5a506c6d54dc9fc284f528762ab84c5961de4d7939375599c0c SHA256 checksum (illumio-technology-add-on-for-splunk_403.tgz) 12174368246da1f47cffc2c73a938407369f7da82b8ea1049c5d9aa9aa9f7c8b SHA256 checksum (illumio-technology-add-on-for-splunk_402.tgz) 87dff82ad35e401c5a9099e200ce602a6a47cbb6b4e9d3b1a31c4724dd1c1c85 SHA256 checksum (illumio-technology-add-on-for-splunk_401.tgz) 2dbf4faba5439c71d3d6f821ca8832393384c1af99780b1ebe0c6c42bc2bc2b2 SHA256 checksum (illumio-technology-add-on-for-splunk_323.tgz) 850815e1ece7005574e83f9f9f7dc532eaba5090e42895d1ff363da265d43c18 SHA256 checksum (illumio-technology-add-on-for-splunk_322.tgz) 5ccf7d0e67ed9a2586780adb65b035892581b3a7cf32c6ccffafb6b7d8da5d96 SHA256 checksum (illumio-technology-add-on-for-splunk_321.tgz) 99382ad43904cbbab5f0b48c61cb902dd8989fc2850f32b30ea5ac17ec10a4ad SHA256 checksum (illumio-technology-add-on-for-splunk_320.tgz) c3aed667b4aec9798ddd975944b78923fb49b7ba28b5ac293ddf5660c53c45c7 SHA256 checksum (illumio-technology-add-on-for-splunk_310.tgz) d84406078195c1e53ef1c403ed994f8b158e687443e108559a9c63c92a7ccd22 SHA256 checksum (illumio-technology-add-on-for-splunk_300.tgz) 54add9aa0e378683e2adfd606ae3d50f71085e3edee6c6b17d5ceb7ad7b3ee2f SHA256 checksum (illumio-technology-add-on-for-splunk_230.tgz) 3aa99e950ff419d0acd6eb089240d8fba831a58dcceea5db2de317865c23769a SHA256 checksum (illumio-technology-add-on-for-splunk_222.tgz) ab81f9c3f14851f1e3a6a90211675ab1373672862b9c62e256bc6e446845b6c1 SHA256 checksum (illumio-technology-add-on-for-splunk_221.tgz) 2f9e6ff969f7ea806cd254068fee544572c57f21a4d932d0c48892d8e5d36b95 SHA256 checksum (illumio-technology-add-on-for-splunk_220.tgz) 8a0df266d231ebe3138545496e192ad8b5699591a05727fe80e007765e7af3f5 SHA256 checksum (illumio-technology-add-on-for-splunk_210.tgz) c42d7c463aeaa5e6f1e22c8736f7a5f9b31feebf84f4005e90c2d9c0510c0fce SHA256 checksum (illumio-technology-add-on-for-splunk_201.tgz) 1c42fa234246ee3c5cc62f7ceb7a6785a507db50bff3a7c742f06c312032b61f SHA256 checksum (illumio-technology-add-on-for-splunk_200.tgz) 7dae5585f5a8b5a9d030d52422cd740018680aa00200e1de157a05e0b760c1dd SHA256 checksum (illumio-technology-add-on-for-splunk_113.tgz) 7d2b4510da6b3f10d4f74f3eeb450a371770f35ca7ee4d899028008c6a57fa29 SHA256 checksum (illumio-technology-add-on-for-splunk_112.tgz) 7af4d181bdc2b23487fc2fe8f9ba83fe903b2ac5be86fbbed86f475bb61ad765 SHA256 checksum (illumio-technology-add-on-for-splunk_102.tgz) 153b0e7ef127cc529883181b17aa3e46b54d5fa154fb5dad3824574e01835660 SHA256 checksum (illumio-technology-add-on-for-splunk_101.tgz) cbda6da82ee7d031d72197b7442d19f06753038789b673bf7a7d240b6ff7f4d3 SHA256 checksum (illumio-technology-add-on-for-splunk_100.tgz) cdd81cdbd305bc8ce790383366b5615d00476104c2b5b09bc927a84f5be29ec2
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Illumio Technology Add-On for Splunk

Splunk Cloud
Overview
Details
The Illumio Technology Add-On for Splunk enriches Illumio Policy Compute Engine (PCE) data with Common Information Model (CIM) field names, event types, and tags. This TA enables Illumio data to be easily used with Splunk Enterprise Security, Splunk App for PCI Compliance, etc.

IMPORTANT: In v4.0.0 and onwards, Syslog prefixes are stripped at index-time for JSON-formatted events. Due to this change, the search-time extractions and transforms for version 4.0.0 and onwards are incompatible with data indexed by previous versions of the TA. See the Upgrade section in the README (or Installation Instructions pane) for more detailed instructions for converting data and custom searches from previous versions of the TA.


TA-Illumio compatibility:
v4.0.3 - Splunk 9.3, 9.2, 9.1, 9.0, 8.2, 8.1 + PCE 21.5, 22.2, 22.5, 23.2, 23.5, 24.2.x and SaaS
v4.0.2 - Splunk 9.3, 9.2, 9.1, 9.0, 8.2, 8.1 + PCE 21.5, 22.2, 22.5, 23.2, 23.5 and SaaS
v4.0.1 - Splunk 9.1, 9.0, 8.2, 8.1 + PCE 21.5, 22.2, 22.5, 23.2 and SaaS
v3.2.3 - Splunk 9.1, 9.0, 8.2, 8.1 + PCE 21.2, 21.5, 22.2, 22.5 and SaaS
v3.2.0 - Splunk 9.1, 9.0, 8.2, 8.1, 8.0, 7.3 + PCE 18.3, 19.1, 19.3, 20.1, 21.2, 21.5

For dashboards with Illumio data, please install the Illumio App for Splunk available at https://splunkbase.splunk.com

Illumio Technical Add-On for Splunk

Overview

The Illumio Add-on for Splunk integrates with the Illumio Policy Compute Engine (PCE). It enriches Illumio data with Common Information Model (CIM) fields for compatibility with other Splunk products and add-ons.

Version - 4.0.3

Supported Splunk versions
* 9.3.x * 9.2.x * 9.1.x * 9.0.x * 8.2.x * 8.1.x

Supported versions of the Illumio Policy Compute Engine (PCE)
* 21.5.x * 22.2.x * 22.5.x * 23.2.x * 23.5.x * 24.2.x * Illumio SaaS PCE (latest)

Supported Splunk Common Information Model (CIM) versions
* 4.x * 5.x

Version - 4.0.1

Supported Splunk versions
* 8.1.x * 8.2.x * 9.0.x * 9.1.x

Supported versions of the Illumio Policy Compute Engine (PCE)
* 21.5.x * 22.2.x * 22.5.x * 23.2.x * Illumio SaaS PCE (latest)

Supported Splunk Common Information Model (CIM) versions
* 4.x * 5.x

Splunk Architecture

The TA-Illumio add-on can be installed in either a standalone or distributed Splunk environment.

Note: Recommendations for the configuration and topology of a distributed Splunk environment are outside the scope of this document. See the documentation on Splunk Validated Architectures for suggestions on topology for distributed deployments.

  • For a standalone deployment, install and configure the TA as described in the Installation section below.

  • For a distributed environment, install the TA to a Splunk Heavy Forwarder.

Note: The TA-Illumio add-on cannot be installed on a Universal Forwarder.

Release Notes

Version 4.0.3

  • Updated Splunk SDK to 2.1.0
  • Updated datatypes in collections.conf to use only string, number, bool and time as per Spunk Cloud vetting standards

Version 4.0.2

  • Added support for configuring search head credentials via TA-Illumio's modular input. This is specific to Splunk Enterprise. Splunk Cloud customers can ignore this step
  • This allows kvstore files to be copied over to remote search heads when data input runs.

Version 4.0.1

  • Removed support for http:// PCE URLs to meet Splunk Cloud compatibility criteria
  • Added missing agent.type, agent.active_pce_fqdn, and agent.target_pce_fqdn fields to illumio_workloads collection and lookup definitions
  • Moved the illumio_quarantine_workload role definition from the app to the TA

Version 4.0.0

  • Syslog prefixes are stripped at index-time for JSON-formatted events

IMPORTANT: Due to this change, the search-time extractions and transforms for version 4.0.0 are incompatible with data indexed by previous versions of the TA. See the v4.0.0 upgrade steps above for more detailed instructions for upgrading from an earlier version.

New Features

  • Added support for label types beyond the default RAEL dimensions
    • Static RAEL field extractions have been removed
  • The TA now seamlessly supports inputs for multiple PCEs as well as multiple organizations within the same PCE cluster
  • Added support for HTTP proxy values when connecting to the PCE
  • Added retry and timeout values for the PCE connection
  • Added flag to specify [tcp] or [tcp-ssl] when creating a new TCP stanza for receiving syslog events
  • System health and PCE status events are now filtered under the new illumio:pce:health sourcetype

Improvements

  • The TA now supports CIM v5.x
  • Updated PCE and Splunk versions supported
  • Updated to the latest version of the Splunk SDK for python
  • Illumio PCE Superclusters are treated the same as any other PCEs for configuration purposes. The input URL may point to a top-level Supercluster FQDN, leader PCE, or member PCE
  • The markquarantine alert action has been renamed illumio_quarantine, and can now be configured with any number of label dimensions
    • The Quarantine Labels parameter in the Illumio input accepts a list of label key:value pairs that form the quarantine policy scope on the PCE. See the workload quarantine action section above for details

Removed Features

  • Python 2.7 is no longer supported
    • The TA now supports python v3.7+
  • Removed the following fields from the modular input spec:
    • private_ip - vestigial field with no functionality in 3.x
    • hostname - no longer necessary due to Supercluster changes
    • api_secret - writing the API secret to passwords.conf now happens via the Splunk REST API when saving the input
    • enabled - inputs can be enabled or disabled from the Splunk UI or by setting the disabled field
  • The illumio.conf custom configuration file has been removed
    • This file previously stored HREF values for quarantine labels, but is no longer needed
  • Removed the following files from TA-Illumio/bin:
    • IllumioUtil.py - replaced with illumio_pce_utils.py and illumio_splunk_utils.py
    • get_data.py - the TA now uses the illumio python library for the PCE API client
    • lib/ and splunklib/ - python libs have been moved under TA-Illumio/lib
    • markquarantine.py - renamed illumio_quarantine.py as the markquarantine action has been renamed illumio_quarantine
  • Removed the illumio:pce:metadata and illumio:pce:ps_details sourcetypes
    • Illumio IP list, Label, Service, and Workload objects are no longer indexed as events
    • Indexing these static objects as events was expensive and could lead to confusing search results. Instead, these objects are added KV stores which are updated on each run of the TA

Note: By default, KV store replication is disabled for these object stores. It is up to the Splunk administrators to determine if replication is necessary for their environments, and override the local collections.conf with replicate = true

* Similarly, port scan details are written to the **illumio_port_scan_settings** collection rather than being indexed as events
  • The $SPLUNK_HOME/var/log/TA-Illumio log directory has been removed. TA logs are now sent to splunkd.log per Splunk best practices for modular inputs
  • The following field extractions have been removed:
    • json_data - no longer relevant with stripped syslog prefixes & JSON KV mode
    • workload_href, agent_href, created_href - where relevant, replaced with CIM field object_id
    • pce_hostname - superceded by pce_fqdn
    • created_hostname, workloads_affected_after, changes_labels_deleted - convenience extractions that are no longer used. If needed, these values are simple to extract manually at search-time using the spath command
    • src_role_label, src_app_label, src_env_label, src_loc_label - replaced with src_label_pairs
    • dest_role_label, dest_app_label, dest_env_label, dest_loc_label - replaced with dest_label_pairs

Version 3.2.3

  • Update Splunk SDK version to latest (1.7.3)

Version 3.2.2

  • Added support for SaaS PCE

Version 3.2.1

  • Removed eventgen.conf from "Illumio Add-on for Splunk" package

Version 3.2.0

  • Modified data collection code to support the supercluster
  • Added supercluster_members.conf file to add members of the supercluster
  • Added "leader_fqdn" field in events only if configured PCE is part of the supercluster
  • Made port number field to be optional during input configuration
  • Enhanced CIM field extractions

EULA

See the EULA document on the Illumio Integrations docs site.

Support

License

Copyright 2023 Illumio, Inc. All rights reserved.

   Licensed under the Apache License, Version 2.0 (the "License");
   you may not use this file except in compliance with the License.
   You may obtain a copy of the License at

       http://www.apache.org/licenses/LICENSE-2.0

   Unless required by applicable law or agreed to in writing, software
   distributed under the License is distributed on an "AS IS" BASIS,
   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
   See the License for the specific language governing permissions and
   limitations under the License.

Release Notes

Version 3.2.4
Jan. 13, 2025
  • Update Splunk SDK version to latest (2.1.0)
Version 4.0.3
Dec. 11, 2024

Version 4.0.3

  • Updated Splunk SDK to 2.1.0
  • Updated datatypes in collections.conf to use only string, number, bool and time as per Spunk Cloud vetting standards
Version 4.0.2
Aug. 14, 2024

This version is aimed to support copying kvstore across to search heads on Splunk Enterprise.

Version 4.0.1
Dec. 1, 2023

IMPORTANT: In v4.0.0/4.0.1, syslog prefixes are stripped at index-time for JSON-formatted events. Due to this change, search-time extractions and transforms for v4.0.x are incompatible with data indexed by previous TA versions. See [v4.0.0 upgrade steps] in the README for details.

v4.0.1

  • Removed support for http:// PCE URLs to meet Splunk Cloud compatibility criteria
  • Added missing agent.type, agent.active_pce_fqdn, and agent.target_pce_fqdn fields to illumio_workloads collection and lookup definitions
  • Moved illumio_quarantine_workload role definition from the App to the TA

v4.0.0

  • Label types beyond default RAEL dimensions. Removed static RAEL field extractions
  • Multiple PCEs and multiple organizations within the same PCE cluster
  • HTTP proxy values when connecting to the PCE
  • Retry and timeout values for the PCE connection
  • Flag to specify [tcp] or [tcp-ssl] when creating a new TCP stanza for receiving syslog events
  • New illumio:pce:health sourcetype
Version 3.2.3
July 7, 2023

Version 3.2.3
* Update Splunk SDK version to latest (1.7.3)

Version 3.2.2
* Added support for SaaS PCE.

Version 3.2.1
* Removed eventgen.conf from "Illumio Add-on for Splunk" package.

Version 3.2.0
* Modified data collection code to support the supercluster.
* Added supercluster_members.conf file to add members of the supercluster.
* Added "leader_fqdn" field in events only if configured PCE is part of the supercluster.
* Made port number field to be optional during input configuration..
* Enhanced CIM field extractions.

Version 3.2.2
May 4, 2022

Fix SaaS Supercluster validation error introduced in 3.2.0 on /health API enpoint, resulting in missing content for
/opt/splunk/etc/apps/TA-Illumio/local/inputs.conf
/opt/splunk/etc/apps/IllumioAppForSplunl/local/inputs.conf

Version 3.2.1
Nov. 17, 2021

-Removed "eventgen.conf" file, which was used to generate dummy data Splunk for demos.

Version 3.2.0
Nov. 11, 2021
  • Modified data collection code to support Illumio Supercluster.
    • Added supercluster_members.conf file to add members of the supercluster.
    • Added "leader_fqdn" field in events only if configured PCE is part of the supercluster.
    • Made port number field to be optional during input configuration..
    • Enhanced CIM field extractions.
Version 3.1.0
July 18, 2020

Illumio Add-on For Splunk v3.1.0
Made TCP-SSL as a default to resolve the Splunk Cloud issue
Added python.version flag to resolve the Splunk Cloud issue
Modified data collection code to handle 503 errors changes
Removed extra forward slash from the API call
* Compatibility with Illumio v20.1, v19.3.2 and 18.2.5

Version 3.0.0
Jan. 25, 2020

Splunk v8 Support
Made Add-on Python23 compatible

Version 2.3.0
Nov. 26, 2019

Changed Illumio API version from v1 to v2
Added support of ingesting data from S3
Added two API calls, services and ip_lists, for Alert Configuration dashboard
Added some field extraction for Alert Configuration dashboard
Changed time extraction and used timestamp field for _time

Version 2.2.2
Sept. 20, 2019

Fixed the issue with saving the new data input on Data Inputs page.

Version 2.2.1
Sept. 6, 2019

Extracted pce_fqdn field for "illumio:pce:metadata" source type
Removed "IP Adress of PCE Node" field from Data Inputs page
Added "Hostname of PCE Node" field on Data Inputs page

Version 2.2.0
July 26, 2019

Extracted new fields for source and destination labels
Added encryption for "API Secret"
Added Validation for "Allowed port scanner Source IP addresses"
Removed "dnslookup" custom command
Added support of both string and integer for PD field
Documented steps of configuration for SUF

Version 2.1.0
June 7, 2019

Certified Addon/App with Illumio v18.3.1 and v19.1
Added support of JSON data format for Illumio Cloud data
Added test script to check the connection with Illumio server
Updated the search time of single value panels to last 60 minutes with a trend line of 24 hours in Security Operations dashboard
Minor Bug Fixes in the panels "Top Workloads with" and "Managed VEN by Operating System"
Fixed the bug related to label filter not considering label type while searching for traffic data in Security Operations dashboard

Version 2.0.1
April 17, 2019

Fixed the issue of fqdn in host_details_lookup table when PCE URL contains special characters.

Version 2.0.0
Sept. 19, 2018

Support for PCE versions 18.1 and 18.2

Version 1.1.3
Jan. 10, 2018
Version 1.1.2
Dec. 2, 2017

Adaptive Response Action
Accept Public/Private IPs of PCE as Modular Input.
PCE Hostnames now available with Syslog Data.
App cert Failure Update for Checking the batch input
PCE V17.2 Support
Minor Bug Fixes

Version 1.0.2
Sept. 12, 2017

Alert Action

Version 1.0.1
Aug. 22, 2017
Version 1.0.0
July 27, 2017

The Illumio Technology Add-On for Splunk enriches Illumio Policy Compute Engine (PCE) data with Common Information Model (CIM) field names, event types and tags.
This add-on enables Illumio PCE data to be used with Splunk Enterprise Security, Splunk App for PCI Compliance, etc.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.