icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Fireeye ETP
SHA256 checksum (fireeye-etp_202.tgz) 51b2cad7c487978004f11ef17ab1c6e6ebf14335349820b46a2c1f042a5ee0a7 SHA256 checksum (fireeye-etp_201.tgz) 8ee381468e390aab5e5a22b739445a2c13ebdbbe30e6e8fce11c6a7c6290dabe SHA256 checksum (fireeye-etp_103.tgz) 07f192929016c95ff0a58879966e7796fd1b702f7f6eae03c8721763d64c2bce

Flag As Inappropriate

soar

Fireeye ETP

Splunk SOAR Cloud
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Cloud Edition provides RESTful APIs for custom integration. The APIs are provided for Advanced Threats, Email Trace, and Quarantine functionalities

Supported Actions Version 2.0.2

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • on poll: Callback action for the on_poll ingest functionality
  • list alerts: Get a list of alerts from the ETP instance
  • get alert: Get details about a specific alert from the ETP instance
  • list email attributes: Get all the attributes from a list of email messages
  • get email attributes: Get the attributes of a particular message with the specified Email Security message ID
  • trace email: Search for Email Message by specifying one or more filters
  • trace message: Search for Email Message by specifying the Queue/Message-ID of the Downstream MTA or the Original Message-ID. At least one parameter must be filled out. All fields are filtered by the IN clause where applicable
  • download email: Download the email header as a text file and add it to the vault
  • download pcap: Downloads all the PCAP files of the alert for a specified alert ID and add the files to the vault
  • download malware files: Download all malware files of the alert for a specified alert ID and add the files to the vault
  • download case files: Download all case files of the alert for a specified alert ID and add the files to the vault
  • remediate emails: Enqueues the message IDs provided in the request for remediation from the user's Office365 mailbox
  • get quarantined email: Download the email file present in the quarantine for the given Email Security message ID and add it to the vault
  • unquarantine email: Release the email file(s) present in the Quarantine within ETP
  • delete quarantined email: Delete the email file(s) present in quarantine for the given Email Security message ID
  • list quarantined emails: Get a list of quarantined emails from a given query filter

Supported Actions Version 2.0.1

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • on poll: Callback action for the on_poll ingest functionality
  • list alerts: Get a list of alerts from the ETP instance
  • get alert: Get details about a specific alert from the ETP instance
  • list email attributes: Get all the attributes from a list of email messages
  • get email attributes: Get the attributes of a particular message with the specified Email Security message ID
  • trace email: Search for Email Message by specifying one or more filters
  • trace message: Search for Email Message by specifying the Queue/Message-ID of the Downstream MTA or the Original Message-ID. At least one parameter must be filled out. All fields are filtered by the IN clause where applicable
  • download email: Download the email header as a text file and add it to the vault
  • download pcap: Downloads all the PCAP files of the alert for a specified alert ID and add the files to the vault
  • download malware files: Download all malware files of the alert for a specified alert ID and add the files to the vault
  • download case files: Download all case files of the alert for a specified alert ID and add the files to the vault
  • remediate emails: Enqueues the message IDs provided in the request for remediation from the user's Office365 mailbox
  • get quarantined email: Download the email file present in the quarantine for the given Email Security message ID and add it to the vault
  • unquarantine email: Release the email file(s) present in the Quarantine within ETP
  • delete quarantined email: Delete the email file(s) present in quarantine for the given Email Security message ID
  • list quarantined emails: Get a list of quarantined emails from a given query filter

Supported Actions Version 1.0.3

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • on poll: Callback action for the on_poll ingest functionality
  • list alerts: Get a list of alerts from the ETP instance
  • get alert: Get details about a specific alert from the ETP instance
  • list email attributes: Get all the attributes from a list of email messages
  • get email attributes: Get the attributes of a particular message with the specified Email Security message ID
  • trace email: Search for Email Message by specifying one or more filters
  • trace message: Search for Email Message by specifying the Queue/Message-ID of the Downstream MTA or the Original Message-ID. At least one parameter must be filled out. All fields are filtered by the IN clause where applicable
  • download email: Download the email header as a text file and add it to the vault
  • download pcap: Downloads all the PCAP files of the alert for a specified alert ID and add the files to the vault
  • download malware files: Download all malware files of the alert for a specified alert ID and add the files to the vault
  • download case files: Download all case files of the alert for a specified alert ID and add the files to the vault
  • remediate emails: Enqueues the message IDs provided in the request for remediation from the user's Office365 mailbox
  • get quarantined email: Download the email file present in the quarantine for the given Email Security message ID and add it to the vault
  • unquarantine email: Release the email file(s) present in the Quarantine within ETP
  • delete quarantined email: Delete the email file(s) present in quarantine for the given Email Security message ID
  • list quarantined emails: Get a list of quarantined emails from a given query filter

Release Notes

Version 2.0.2
April 28, 2025
  • Update Python dependencies for vulnerabilities, package updates, and platform built-in removals
  • Update Python dependencies for Python 3.13 support
  • Update NOTICE file with updated dependencies
  • Apply pre-commit fixes
Version 2.0.1
Feb. 14, 2022
  • Compatibility changes for Python 3 support
Version 1.0.3
Sept. 21, 2021

Fireeye ETP Release Notes - Published by Robert Drouin January 19, 2021

Version 1.0.3 - Released January 19, 2021

  • Initial Release

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.