icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading TheHive/Cortex
SHA256 checksum (thehivecortex_390.tgz) 49a8ea208e4435e2db0bae7f99aa46802407ded55d7c971a454385d0fa69e6fc SHA256 checksum (thehivecortex_382.tgz) df0918523a12a011d8a4d79eaf57490609199b6c1762928f838790ad7dcf5339 SHA256 checksum (thehivecortex_381.tgz) d158e958dee406fead3108d181e7be5ee10c8338b7d4a97d417c33b7176ca91a SHA256 checksum (thehivecortex_380.tgz) f3d9aa8481d5b7c76a6dd130ec43c9308ed9c265dcd7e68ece48616a9f24feba SHA256 checksum (thehivecortex_370.tgz) 4c35a3ddfea0e3aeb88bee745aac97b37030e4e25d12e39c529225923ca92359 SHA256 checksum (thehivecortex_362.tgz) d0a192d798caba583f1b1b30fe97c85733f47f4df16e46749fa87336db1c636e SHA256 checksum (thehivecortex_32.tgz) a5b519a3ce8cad5372f77357ceb78ba973f5ba501f8ed395a44eb7e9f95f0eea SHA256 checksum (thehivecortex_232.tgz) e43500f4dc6f914dd07d7d8012bb80a0d5610e53f9db520579c7ad28024b318f
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

TheHive/Cortex

Splunk Cloud
Overview
Details
This TA allows to add interaction features between TheHive or Cortex (https://www.strangebee.com/) and Splunk. It allows to retrieve all kind of information from TheHive/Cortex and to perform actions on these instances using Splunk, from a search or from a predefined dashboard.

This TA is supporting only TheHive 5. For having an app supporting TheHive 3 or 4, please check the oldest releases. It's also supporting the Cortex 3 version.

More information here: https://github.com/LetMeR00t/TA-thehive-cortex

The objective is to interface a SIEM tool such as Splunk in order to be able to perform automated tasks on observables/IOCs or TTPs.
This TA has been designed in such a way that :

  • You can pull events periodically from TheHive about the different cases/alerts that were created or updated
  • You can create new alert or case from Splunk in TheHive using the power of Splunk whether in a search or in a predefined dashboard.
  • You can run a function in TheHive from an alert action
  • You can interface Splunk Enterprise Security with TheHive
  • You can retrieve information from Cortex about the different jobs that are being performed on the scanners.
  • You can run new tasks from Splunk in Cortex using the power of Splunk whether in a search or a predefined dashboard.

If you need any documentation or help, please visit the related Github : https://github.com/LetMeR00t/TA-thehive-cortex

Release Notes

Version 3.9.0
Sept. 16, 2025

Release Notes for v3.9.0

  • Fix: #112, adding the possibility to select the backslashes sanitization in the parameters
  • Fix: #102, correlation searches actions in Splunk ES are now fixed and can be used with this TA
  • Refactor: Few code optimisations

Note: You can upgrade from v3.2 to v3.9.0 without the intermediate versions.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.9.0

Version 3.8.2
June 26, 2025

Release Notes for v3.8.2

  • Fix: Resolve backfill execution issues for alerts/cases
  • Fix: Resolve tasks event correctly
  • Refactor: Upgrade thehive4py library to v2.0.0b11 (revised for Splunk)

Note: You can upgrade from v3.2 to v3.8.2 without the intermediate versions.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.2

Version 3.8.1
April 22, 2025

Release Notes for v3.8.1

  • Feature: Support "links" as extraData coming from TheHive 5.5
  • Fix: Double identical values issue in inputs

Note: You can upgrade from v3.2 to v3.8.1 without the intermediate versions.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.1

Version 3.8.0
April 19, 2025

Release Notes for v3.8.0

  • Feature: Support the "extraData" options when recovering data from alerts/cases using inputs
  • Feature: Rationalize inputs by having multipleSelect instead of single one to avoid having too many inputs to configure
  • Feature: The "customFields" field used in inputs have been rework to make it simplier to search on Splunk and reduce the size of the information
  • Feature: Tasks recovered from cases have now their own sourcetype as it's considered as a dedicated object in TheHive (Pages are still linked to their case information)
  • Feature: Support searchbnf.conf file for custom commands information and auto-completion in SPL

Additional fixes have been provided.
See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.8.0

Version 3.7.0
March 21, 2025

Release Notes for v3.7.0

  • Feature: Add the capability to backfill data from the past using inputs (documentation available on Github for inputs)
  • Feature: Upgrade splunklib
  • Fix: Format rendering in logs
  • Fix: Token usage in dashboards (#106)

Note: You can upgrade from v3.2 to v3.7.0 without the v3.2/v3.3/v3.4/v3.5/v3.6.*.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.7.0

Version 3.6.2
Jan. 31, 2025

Release Notes for v3.6.2

  • Feature: Add the capability to remove several keys of the events or truncate large values within an event with a max size parameter for log collection
  • Fix: warn/warning log error
  • Fix: Remove a third party visualization not supported anymore

Note: You can upgrade from v3.2 to v3.6.2 without the v3.2/v3.3/v3.4/v3.5.

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.6.2

Version 3.2
Dec. 19, 2023

Release Notes for v3.2

  • Feature: Refinement of the composite fields (fields with colons) by adding the possibility to enrich observables information from the Splunk search #79
  • Feature: Improve the code/documentation regarding the usage of the fields "th_severity", "th_tlp" and "th_pap" used to set values for an alert/case directly from the search #74
  • Bug: An issue was fixed regarding the non processing of remaining alerts when one alert wasn't created (due to a duplication for instance) #78
  • Bug: An issue was fixed regarding the exclusion of the alert/case tags from the markdown generated table in the description #77
  • Bug: An issue was fixed regarding missing carriage return/newline/separator in the markdown generated table in the description #76

See the full release notes directly on Github: https://github.com/LetMeR00t/TA-thehive-cortex/releases/tag/v3.2

Version 2.3.2
May 18, 2023
  • Add support for having certificates in base64 encoded directly in the GUI
  • Add support to restrict access to storage/passwords to only the TA-thehive-cortex app

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.