-Updated the SPL for the widget based on the latest changes in Qualys TA EDR data input.
-Compatibility for Splunk Cloud
The Qualys EDR App for Splunk Enterprise is the next generation of earlier IOC App for Splunk.
This version of Qualys EDR app provides you an information dashboard, which gives quick information bites on Actionable Events, Malware Detections by Category, Affected Assets etc. It also has widgets to show you top malware Detections, malware Files etc.
You also have options to search for All EDR events which will show you raw events indexed in Splunk.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.