icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading GreyNoise for SOAR
SHA256 checksum (greynoise-for-soar_300.tgz) 617770a795a5c5e0708a42ff50a64e6d1a15084ff8892f9d66e38516d2d7d72e SHA256 checksum (greynoise-for-soar_233.tgz) 38344dbe92a0edbbc338f5b3b5f1c377ea15404867133218cd0ce9a4a3263930 SHA256 checksum (greynoise-for-soar_232.tgz) 721126b12995992291421130f2071595c57b1cdd99a28e54c50487d8e6b749b8 SHA256 checksum (greynoise-for-soar_231.tgz) c17e05123f15b724befa81be2897422bcc05431d5c3ded051d11d7b1eacff068 SHA256 checksum (greynoise-for-soar_230.tgz) 725482cc90d432548ca1b8908bcb1fa65e4395e1fb70db8f5cfc03a808624e67 SHA256 checksum (greynoise-for-soar_220.tgz) 7c15698b2453662765888bf2fa508a038cfb8d406c1e49030e75cabbf8b05df4

Flag As Inappropriate

soar

GreyNoise for SOAR

Splunk SOAR Cloud
Overview
This app provides investigative capabilities using the GreyNoise plugin and supports receiving alerts and feeds via webhook from GreyNoise

Supported Actions Version 3.0.0

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • noise ip timeline: GreyNoise IP Timeline lookup for events matching a specific field
  • get cve details: Retrieve details about a specific Common Vulnerabilities and Exposures (CVE)

Supported Actions Version 2.3.3

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • riot lookup ip: Lookup IP using GreyNoise's RIOT endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • community lookup ip: Lookup IP using GreyNoise's free community endpoint
  • similar noise ips: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool
  • noise ip timeline: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool

Supported Actions Version 2.3.2

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • riot lookup ip: Lookup IP using GreyNoise's RIOT endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • community lookup ip: Lookup IP using GreyNoise's free community endpoint
  • similar noise ips: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool
  • noise ip timeline: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool

Supported Actions Version 2.3.1

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • riot lookup ip: Lookup IP using GreyNoise's RIOT endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • community lookup ip: Lookup IP using GreyNoise's free community endpoint
  • similar noise ips: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool
  • noise ip timeline: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool

Supported Actions Version 2.3.0

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • riot lookup ip: Lookup IP using GreyNoise's RIOT endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • community lookup ip: Lookup IP using GreyNoise's free community endpoint
  • similar noise ips: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool
  • noise ip timeline: Lookup Similar internet scanner IP using GreyNoise's IP Similarity tool

Supported Actions Version 2.2.0

  • test connectivity: Validate the asset configuration for connectivity using the supplied configuration
  • lookup ip: Lookup IP using GreyNoise API Quick Check Endpoint
  • riot lookup ip: Lookup IP using GreyNoise's RIOT (Rule It OuT) endpoint
  • ip reputation: Get full GreyNoise reputation and context for a specific IP
  • gnql query: Use the GreyNoise Query Language to run a query
  • lookup ips: Lookup IPs using GreyNoise API Multi Quick Check Endpoint (comma-separated, limit 500 per request)
  • on poll: Get details on a specific GNQL query
  • community lookup ip: Lookup IP using GreyNoise's free community endpoint

Release Notes

Version 3.0.0
Aug. 20, 2025
  • Upgraded GreyNoise SDK to version 3.0.1
  • Added webhook support to receive Alerts and Feeds data from GreyNoise
  • Added 'get cve details' action to retrieve CVE information from GreyNoise
  • Added the following parameters to the 'gnql query' action:
  • exclude_raw
  • quick
  • Updated parameters in 'noise ip timeline' action:
  • Removed: limit
  • Added: field
  • Added: granularity
  • Removed the following actions:
  • community lookup ip (use 'ip reputation' action instead)
  • riot lookup ip (use 'ip reputation' action instead)
  • similar noise ips
Version 2.3.3
April 29, 2025
  • Update Python dependencies for vulnerabilities, package updates, and platform built-in removals
  • Update Python dependencies for Python 3.13 support
  • Update NOTICE file with updated dependencies
  • Apply pre-commit fixes
Version 2.3.2
May 22, 2023
  • Fixes noise ip timeline description
  • Updates GreyNoise SDK to version 2.0.1
Version 2.3.1
April 24, 2023
  • Updates output listing for ip reputation and riot ips commands
Version 2.3.0
April 5, 2023
  • Updates to the 2.0.0 GreyNoise SDK
  • Adds IP Similarity action
  • Adds IP Timeline action
  • Fixed miscellaneous JSON and documentation issues
Version 2.2.0
March 17, 2022
  • Updated the app to use the latest GreyNoise SDK
  • Fixed miscellaneous JSON and documentation issues

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.