icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading SOC Prime CCM App for Splunk - Optimized
SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_207.tgz) 5ebc74ec2d9c3c7236e08cd772738b12146a59fdc42ae1d400f93919525c8e6c SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_206.tgz) 3344043e9ee5e3b0e1be5edc09ae071e5b8f184c52156c07f0be72bc729f5c6c SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_205.tgz) 3ec9ec899b22f0a0b77979868584891623fd8bfe5c0ac6bab4e6b65b81126602 SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_204.tgz) 8bcddd5b49efa73fae91375ff883169ce187a99e54b9ce5892ce2231a61285ce SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_203.tgz) dd65445e74a2f4e81bd80a0caa7eee9fa5dc61da8d207b351fdec4dec346380c SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_202.tgz) 9846ee1ec877bb2ce2568ebe1e5043bd0437036d0407f503824c37e34b51be78 SHA256 checksum (soc-prime-ccm-app-for-splunk-optimized_201.tgz) 5b7c0956b0865885b3175998965e73c7fc739c3ba9ff02f25a4772793625c8f0
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

SOC Prime CCM App for Splunk - Optimized

Splunk Cloud
Overview
Details
With SOC Prime CCM App for Splunk - Optimized, you can continuously stream new rules and rule updates from the SOC Prime Platform to your cloud or on-prem Splunk instance.

To enable rule streaming, configure Jobs in the Continuous Content Management (CCM) module of the SOC Prime Platform and specify them in the App's data input. Jobs are configured with Content Lists to select rules for deployment, Presets to automatically modify the rules' parameters, and Filters to include additional conditions. You can also set up and apply Custom Field Mapping profiles to make the names of indexes, fields, and even field values in the rule code match your custom data schema.

To obtain rules via the CCM module and stream them into your environment, you need access to the SOC Prime CCM API. For more details on the API, see our Platform Guides: https://help.socprime.com/en/articles/6265791-api (to open the Guides, you need to be logged in to your SOC Prime Platform account).

SOC Prime CCM App for Splunk - Optimized is SOC Prime CCM App for Splunk v2.0.1 or later. You can find earlier versions of the App here: https://splunkbase.splunk.com/app/5725.

SOC Prime CCM App for Splunk - Optimized

Description

With SOC Prime CCM App for Splunk - Optimized, you can continuously stream new rules and rule updates from the SOC Prime Platform to your cloud or on-prem Splunk instance.

To enable rule streaming, configure Jobs in the Continuous Content Management (CCM) module of the SOC Prime Platform and specify them in the App's data input. Jobs are configured with Content Lists to select rules for deployment, Presets to automatically modify the rules' parameters, and Filters to include additional conditions. You can also set up and apply Custom Field Mapping profiles to make the names of indexes, fields, and even field values in the rule code match your custom data schema.

To obtain rules via the CCM module and stream them into your environment, you need access to the SOC Prime CCM API. For more details on the API, see our Platform Guides: https://help.socprime.com/en/articles/6265791-api (to open the Guides, you need to be logged in to your SOC Prime Platform account).

SOC Prime CCM App for Splunk - Optimized is SOC Prime CCM App for Splunk v2.0.1 or later. You can find earlier versions of the App here.

Requirements

SIEM: Splunk v. 8.x or higher, or Splunk Cloud.
Note: If you have an all-in-one Splunk environment, use this guide to install the app. If you have a distributed Splunk environment, please contact SOC Prime support for help with installation since it may be specific to your configuration.

Installation

There are two ways of installing the app: via the Splunk app listing or manually with the add-on package. If you already have v2.0.0 or older of this App installed, remove it before installing the new version.

To install the app via the listing, follow these steps:

  1. Open the Splunk Web Console.
  2. Select the gear icon on the Apps tab.
  3. Click the Browse more apps button.
  4. Type "SOC Prime CCM App for Splunk - Optimized" in the search field to find the app and proceed to its installation in your environment.

To install the add-on manually, follow these steps:

  1. Open the Splunk Web Console.
  2. In the Splunk Web Console, select the Apps tab.
  3. Click the Install app from file button.
  4. Select the "SOC Prime CCM App for Splunk - Optimized" package and proceed to its installation in your environment.

After successful installation, the app should appear as SOC Prime CCM App for Splunk - Optimized in Splunk’s Apps menu.

Configuration

After installation, configure the rule import on the Inputs tab:

  1. Select SOC Prime CCM App for Splunk - Optimized in the main Apps menu.
  2. Select the Inputs tab.
  3. Click Create New Input.
  4. Fill in the parameters.

Release Notes

Version 2.0.7
Oct. 3, 2025
  • 2.0.7 — Updates:
    • Implemented changes to comply with the updated Splunk Cloud Platform compatibility
Version 2.0.6
Feb. 7, 2025
  • 2.0.6 — Updates:
    • Implemented changes to comply with the updated Splunk Cloud Platform compatibility
Version 2.0.5
Jan. 15, 2025
  • 2.0.5 — We've made some updates:
    • Updated libraries to comply with the new Splunkbase requirements.
    • Made some optimizations.
    • Added the CCM API URL input parameter so that the user can set a non-default URL.
Version 2.0.4
April 2, 2024
  • 2.0.4 — We've made some updates:
    • Implemented changes to comply with the updated Splunk Cloud Platform compatibility requirements.
    • Changed the convention of Rule naming: using the case ID in the rule name is not required anymore.
    • Added the possibility of assigning the ownership of installed Rules to a specific user.
    • Fixed bugs.
Version 2.0.3
Jan. 31, 2024
  • 2.0.3 — We've made some updates:
    • Implemented changes to comply with the updated Splunk Cloud Platform compatibility requirements.
    • Fixed bugs.
Version 2.0.2
Oct. 25, 2023
  • 2.0.2 — We've made some updates:
    • Implemented changes to comply with the updated Splunk Cloud Platform compatibility requirements.
    • Fixed bugs.
Version 2.0.1
Jan. 31, 2023
  • 1.0.0 — Initial release of the SOC Prime CCM App for Splunk providing functionality to import Alerts from the SOC Prime TDM Platform.
  • 1.0.1 — General minor improvements.
  • 1.0.3 — We've made several updates:
    • Fixed filters in dashboards
    • Resolved the issue with rule names that could lead to rule duplication
    • Fixed and optimized the API script
  • 2.0.0 — We've introduced several substantial improvements:
    • Streamlined the configuration of content to be deployed by introducing Jobs that replace all the separate settings used before. Now, you set up Jobs in SOC Prime Patform's CCM (adding Content Lists, Field Mappings, Presets, and Configs), and specify the Jobs in the App's data input.
    • Removed deprecated options (Content List Name, Mapping Name, Preset Name, Alt Translation Config) from data input parameters.
    • Added data input parameters to configure Jobs as well as rule exceptions, proxy, and distributed deployment.
  • 2.0.1 — We've made some updates:
    • Added integration with Splunk Enterprise Security.
    • Added the Inputs tab where you can configure data inputs.
    • Added the Configuration tab where you can configure proxy and logging level.
    • Fixed bugs.

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.