icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

Thank You

Downloading Splunk
SHA256 checksum (splunk_2201.tgz) 11320e157d9b72defbb22800a2a61f884efd0b0f4941969ba2a763924347a17a SHA256 checksum (splunk_2200.tgz) 0e83ec395bc4e5706f757d232ebed3b623818544e99f326a2940cc73655092d5 SHA256 checksum (splunk_2180.tgz) 32e6aff24cd4a1d37c79642cb2f79d880b06ad51e3e51843e4e5c9e164e2a994 SHA256 checksum (splunk_2170.tgz) c0e72e8822061557040f6d29954da76f63cca403d474c55b568af79a65a3235a SHA256 checksum (splunk_2162.tgz) 8c915cc96679e58c7377805b5e6ffffd6ac20900c92f95be465bf5ebc75b4d63 SHA256 checksum (splunk_2161.tgz) 0bc7e5970582352ef9e75fba8aa90201ff8f2431c73223a45e84c76e1ac76d87 SHA256 checksum (splunk_2160.tgz) c759ea76ea8c87ec534537f243b0e3bac73cb98510077543cec229f40d23d8e4 SHA256 checksum (splunk_2151.tgz) 0a2be349030f113e4483772331278472141f25308247c8a7bdc58e84f4be5cfb SHA256 checksum (splunk_2150.tgz) 242de48a2ef685cfdf192b8e14afef2a3b7e54026e53e8fb0b630666508b6ada SHA256 checksum (splunk_2140.tgz) 35d923c660a22228acbb59efb32599a2ac368a8f9ba16633418fa606d74ed7d2 SHA256 checksum (splunk_2130.tgz) 21e78820d29a36e7eb8f00ba7d927bc8148fb1400f695024ea1b1e723f921241 SHA256 checksum (splunk_2120.tgz) c2e04ff5b588413e6b2085cf0998e699a0f611a5c35cb75e4bc73dc6ade12df4 SHA256 checksum (splunk_2111.tgz) cab9eac617801a0401e65506bfe38e3088849d0cf5b271dec7618efc68632c94 SHA256 checksum (splunk_2110.tgz) 4300d54ffe289ce23b27e2a51f23b58db4cd5105034350edb53eaa658b374e71 SHA256 checksum (splunk_2100.tgz) fc5be36225a1530c6ed53c707ddb6d7c20a9ec552c5e9aff68fdd6dacf70bcd4 SHA256 checksum (splunk_290.tgz) 5a7d21f22e68fe4ae1d595aff6d3f5eada347b5279cd017d12755b20197f7b15 SHA256 checksum (splunk_280.tgz) c2a084856af0ec44971dc7a016f1b5e0ed70ffedb28e186d12cb1d2b5db2c6a4 SHA256 checksum (splunk_270.tgz) 659f4c951dd024104c03733e4199dd5b12f28f8a895643a247377ce0838230fb SHA256 checksum (splunk_267.tgz) b24ba4da58172dec47025a05766a458c3013f13800b4234b31c9af732e6a7cd2 SHA256 checksum (splunk_266.tgz) 9fcc796ef552ffbf0289f8a450e16b4ef87ebeceb9e41fb640f202df89a730df SHA256 checksum (splunk_248.tgz) 4b9dff4d996ed0cedd8541b74bb2842e8ba27e2486682b396082f53534b1ef23 SHA256 checksum (splunk_233.tgz) 12a262b6c2ff9f721dc13d34bcb96a5bc5f0495949cf4d4fe3a3ea93ad6119aa SHA256 checksum (splunk_223.tgz) a1a1a763e052183a15158c91743d015755d0598e79dab1d39ffe5f2f8b78b73d SHA256 checksum (splunk_216.tgz) f4ff4029f46ac95dd720ade32820d94caa255a467fcbefe06541197665c1e2a3 SHA256 checksum (splunk_213.tgz) c608f8341722fcbef2c760f78fab75d5f93d57c76e0d616ab2273498138c7e5d

Flag As Inappropriate

soar

Splunk

Splunk SOAR Cloud
Splunk Built
Overview
This app integrates with Splunk to update data on the device, in addition to investigate and ingestion actions

Supported Actions Version 2.20.1

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.20.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.18.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.17.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.16.2

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.16.1

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.16.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.15.1

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.15.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.14.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.13.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.12.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.11.1

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.11.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.10.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.9.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.8.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.7.0

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.6.7

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.6.6

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.4.8

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.3.3

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.2.3

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.1.6

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Supported Actions Version 2.1.3

  • test connectivity: Validate the asset configuration for connectivity. This action logs into the device to check the connection and credentials
  • get host events: Get events pertaining to a host that have occurred in the last 'N' days
  • on poll: Ingest logs from the Splunk instance
  • run query: Run a search query on the Splunk device. Please escape any quotes that are part of the query string
  • update event: Update a notable event
  • post data: Post data to Splunk

Release Notes

Version 2.20.1
April 11, 2025
  • Update Python dependencies for vulnerabilities, package updates, and platform built-in removals
  • Update Python dependencies for Python 3.13 support
  • Update NOTICE file with updated dependencies
  • Apply pre-commit fixes
Version 2.20.0
Jan. 16, 2025
  • Added 'use_event_id_sdi' parameter to asset config to allow updated event ingestion into the original container
  • Added parameter in run query action to optionally remove the "_raw" field [PAPP-26864]
Version 2.18.0
Oct. 15, 2024
  • Added 2 new fields ("disposition" and "integer_disposition") to "update event" action
Version 2.17.0
Sept. 25, 2024
  • Added 'splunk_job_timeout' parameter to asset config [PAPP-34684]
Version 2.16.2
June 28, 2024
  • Fixed Django template, ifnotequal tag was deprecated.
Version 2.16.1
Feb. 14, 2024
  • Changed logic in 'run query' action in order to decrease memory usage [PAPP-32609]
Version 2.16.0
Jan. 25, 2024
  • Documentation update for steps to allow edit_tcp capability for a user [PAPP-31540]
  • Bug fix for 'on poll' cef field names [PAPP-30430]
  • Bug fix for accessing vault temp directory path [PAPP-32416]
Version 2.15.1
Dec. 7, 2023
  • Updated dependency packages, removed future [PAPP-31089]
Version 2.15.0
June 22, 2023
  • Bug fix for removing temp files [PAPP-30430]
  • Added a new feature to include both CEF and original CIM field [PAPP-30037]
Version 2.14.0
April 19, 2023
  • Fixed the issue related to source_data_identifier [PAPP-29653]
Version 2.13.0
Nov. 4, 2022
  • Fixed load balancer sticky sessions related cookie persistence bug [PAPP-27448, PAPP-26097]
Version 2.12.0
Oct. 11, 2022
  • Added search_mode parameter to "run query" action with fast, verbose, and smart as possible values [PAPP-10085]
  • Update Splunk SDK to 1.7.2 and changed ResultsReader to JSONResultsReader [PAPP-27658]
Version 2.11.1
Sept. 9, 2022
  • Improved error logging
  • Removed python 2 related code
Version 2.11.0
Sept. 7, 2022
  • Added token-based authentication workflow
  • Replaced an endpoint for test connectivity action
  • Fixed miscellaneous proxy-related issues
Version 2.10.0
April 27, 2022
  • Fixed an issue in On Poll action where the index time was not honored during scheduled ingestion [PAPP-25411]
Version 2.9.0
April 2, 2022
  • Added 2 new fields ("start_time" and "end_time") to "run query" action [PAPP-24566]
Version 2.8.0
March 9, 2022
  • Added a sleep time between REST calls to improve the performance [PAPP-23575]
Version 2.7.0
Feb. 17, 2022
  • Added a new 'attach_result' parameter in 'run query' action [PAPP-8315]
Version 2.6.7
Feb. 7, 2022
  • Added support for Python 3.9
Version 2.6.6
Jan. 20, 2022

Splunk Release Notes - Published by Splunk January 20, 2022

Version 2.6.6 - Released January 20, 2022

  • Changed the hashing algorithm to SHA256 when running in FIPS mode [PAPP-21816]
Version 2.4.8
Oct. 19, 2021

Splunk Release Notes - Published by Splunk October 19, 2021

Version 2.4.8 - Released October 19, 2021

  • Added a new 'Remove CEF fields having empty values from the artifact' configuration parameter [PAPP-9257]
Version 2.3.3
Sept. 21, 2021

Splunk Release Notes - Published by Splunk August 06, 2021

Version 2.3.3 - Released August 06, 2021

  • Updated the 'update event' action's status based on the "success" key in response [PAPP-9587]
  • Modified the code to re-connect based on retry limit in case of "Session not logged in" issue [PAPP-17690]
  • Modified the on-poll action to ingest updated/deleted artifacts in the existing container [PAPP-18788]
  • Updated the document for Update event action with the required role and permission
Version 2.2.3
Sept. 21, 2021

Splunk Release Notes - Published by Splunk August 06, 2021

Version 2.2.3 - Released July 13, 2021

  • Added support for custom status ID in the integer status parameter of the 'update event' action [PAPP-9598]
  • Bug fix in the 'run query' action [PAPP-13769]
  • Allow 0 for the 'Max events to ingest for Scheduled Polling' configuration parameter [PAPP-11483]
  • Fix for the 'Values to append to the container name' configuration parameter [PAPP-11072] [PAPP-17977]
  • Handled extra commas in the display parameter of the 'run query' action [PAPP-17228]
Version 2.1.6
Sept. 21, 2021

Splunk Release Notes - Published by Splunk August 06, 2021

Version 2.1.6 - Released June 24, 2021

  • Fixed the start_time field in the artifact [PAPP-17613]
Version 2.1.3
Sept. 21, 2021

Splunk Release Notes - Published by Splunk August 06, 2021

Version 2.1.3 - Released April 14, 2021

  • Fixed a bug which caused the app to ignore the Global Proxy Settings [PAPP-11360]
  • Fixed a bug during ingestion if an event had multiple associated severities [PAPP-12153]

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.