icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

Classic Splunkbase is heading into retirement…

Splunkbase Classic has been deprecated and will be deactivated on February 18, 2026.
The new version of Splunkbase introduces improved search and discoverability, faster performance, enhanced accessibility, and a modern interface. Start exploring the new experience today!
Splunkbase Classic has been deprecated and will be deactivated on February 18, 2026. Go to new Splunkbase.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Machine Learning Cloud Service Add-on for Enterprise Security
SHA256 checksum (machine-learning-cloud-service-add-on-for-enterprise-security_120.tgz) 7e19fc862a2187c34e7566d577bea8752712430c62a604daad5027e2dc25b497 SHA256 checksum (machine-learning-cloud-service-add-on-for-enterprise-security_110.tgz) b6bd0e801f5bd488129c7f8555e1af5ac10236e30eec7c5228dac63146804ee2 SHA256 checksum (machine-learning-cloud-service-add-on-for-enterprise-security_101.tgz) f934e0c520e9980a9c7938ff7624871d56125e13aa812efb276062befe1d8ebb SHA256 checksum (machine-learning-cloud-service-add-on-for-enterprise-security_095.tgz) 8d8fb42319fc2ec997b42c3e35b754aa1b4e79d426ad53f23071213f1dc249d3 SHA256 checksum (machine-learning-cloud-service-add-on-for-enterprise-security_094.tgz) 4a9894ee587696699cb467a4d4ab0fdd8a193eab56f688520286560796d28393
To install your download
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate

splunk

Machine Learning Cloud Service Add-on for Enterprise Security

Splunk Labs
This app has been archived. Learn more about app archiving.
Overview
Supporting Add On for the detection of ransomware leveraging advanced machine learning and transfer learning techniques.

Release Notes

Version 1.2.0
April 22, 2021
  • Fixed issue with what-if dashboard using outdated macro apply_base_local
  • Fixed issue with DGA correlation search returning too many results increased threshold in confidence_filter(4) macro to 0.90
Version 1.1.0
Jan. 25, 2021
  • Updated model training configuration for dga model retraining to only use class=confirmed_dga
  • Updated confidence filter and apply_base_local macros to be more expansive for future use cases
  • Added botnet model for the detection of bots in the All_Traffic datamodel
  • Updated model retrieval script to support new $class$ parameter
  • Improved logging in model retraining
  • Added botnet intelligence colllection & dashboard
Version 1.0.1
Nov. 25, 2020
  • Updated base model file in the app and cloud service
  • Updated User Guide Dashboard with youtube video link
  • Updated color scheme for Splunkbase
  • Improved logic in search (0.9.5v)
  • Migrated excess files for model creation out of the app.
Version 0.9.5
Oct. 28, 2020

Updates & Fixes
- Changed Syntax in ml_intel threat collection to use update=true|false instead of 1 or 0 for filtering and clarity
- Updated Threat Intelligence Review Dashboard to Provide a filtering option (search for domains, filter unlabelled domains)
- Improved the KV Store Audit functionality for users that are changing the labels (DGA|LEGIT) in the ml_intel collection
- Update the correlation search to include CDN_INTEL for filtering out false positives earlier in the process
- Added a one-time use migration search to update the ml_intel collection to the new update=true or false values
- Improved Z^2 Daemon's Deduplication search to maintain update status and other fields
- Added a new field to ml_intel to store the confidence of a class prediction, this is overwritten when the class is confirmed by the analyst with confirmed_dga or confirmed_legit
- Updated documentation with steps to add a view to the ES menu bar. (Known bug with tablebutton.js not loading when viewing in the ES app context.)

Version 0.9.4
Sept. 14, 2020

--- Pre-GA Release ---
This add on is the release candidate for the GA version that will go live at .conf20.
It requires the following apps to work fully:
Enterprise Security 6.x: https://splunkbase.splunk.com/app/263/
Url Toolbox 1.8: https://splunkbase.splunk.com/app/2734/
Machine Learning Toolkit 5.2: https://splunkbase.splunk.com/app/2890/
Python for Scientific Computing 2.0: https://splunkbase.splunk.com/app/2882/


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.