icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading FortiNDR Cloud Add-on for Splunk
SHA256 checksum (fortindr-cloud-add-on-for-splunk_113.tgz) 465968656e4b7de0d1ac69906c81a2f5e8369a64daeee0fc4d827bbf4f79ec09 SHA256 checksum (fortindr-cloud-add-on-for-splunk_112.tgz) d4c3c73c6abf0764d3e70f6111eeb81aa6108c2d162203adb2665ebb5b6a18d7 SHA256 checksum (fortindr-cloud-add-on-for-splunk_111.tgz) d0193dc994d5ab09d682bdc6cd041c8d402b3f702d21d74ec3b29b44f81cbb49 SHA256 checksum (fortindr-cloud-add-on-for-splunk_110.tgz) 7c7b90cdb0e3ea0774006bb6e1c10af515b7886af0e3dc183486200d2a859637 SHA256 checksum (fortindr-cloud-add-on-for-splunk_105.tgz) 7c77f8721288834f108132bd366f980470b78323e0599c02b929caae8ac13be9 SHA256 checksum (fortindr-cloud-add-on-for-splunk_104.tgz) c8d5bcc6581a1bce7e4bc28104530d90768d9a4c9db726b3cf08689a02fbea37 SHA256 checksum (fortindr-cloud-add-on-for-splunk_103.tgz) 6e9867ef2ccc60ea3a7067282af99f46c3fea21e5607086ffd6670d5266a44a0 SHA256 checksum (fortindr-cloud-add-on-for-splunk_102.tgz) 63102b31ff33e1694a5eb9dcde4ea1e47a2a15e3a6cd6a6e6a40509a9254f6f8 SHA256 checksum (fortindr-cloud-add-on-for-splunk_101.tgz) 23461c777b8f25524ee72da3d57bef579c7b91543b7227a0fa7de11469b333e1 SHA256 checksum (fortindr-cloud-add-on-for-splunk_100.tgz) 2aa2e56a870bafaf931f50a9755f7b9ab8ef384efeb62c34049f233ff86581f0
To install your download
To install apps and add-ons from within Splunk Enterprise
  1. Log into Splunk Enterprise.
  2. On the Apps menu, click Manage Apps.
  3. Click Install app from file.
  4. In the Upload app window, click Choose File.
  5. Locate the .tar.gz file you just downloaded, and then click Open or Choose.
  6. Click Upload.
  7. Click Restart Splunk, and then confirm that you want to restart.
To install apps and add-ons directly into Splunk Enterprise
  1. Put the downloaded file in the $SPLUNK_HOME/etc/apps directory.
  2. Untar and ungzip your app or add-on, using a tool like tar -xvf (on *nix) or WinZip (on Windows).
  3. Restart Splunk.
After you install a Splunk app, you will find it on Splunk Home. If you have questions or need more information, see Manage app and add-on objects.

Flag As Inappropriate

splunk

FortiNDR Cloud Add-on for Splunk

Splunk Cloud
Overview
The FortiNDR Cloud Add-on for Splunk allows administrators to incorporate the network telemetry data collected and analyzed by FortiNDR Cloud into their Splunk deployment. This app leverages the fully RESTful APIs to interact with the cloud backend to introduce specific data sets into Splunk. With this app, raw events can also be retrieved from the AWS S3 Buckets to import specific network events and all the associated metadata into Splunk.

Release Notes

Version 1.1.3
Jan. 30, 2025
Version 1.1.2
Nov. 25, 2024

Removing option to filter training account related events.

Version 1.1.1
Nov. 15, 2024

Added multi-region support.
Deprecation of the entities information enrichment for detections and events input. The entity’s information can only
be retrieved with the entities input.
Added the Mitre Attack IDs and the rule's URL to the FortiNDRCloud:Detections Splunk events
Adding Support for Splunk 9.2 and 9.1 (For Splunk 9.3 use version 1.1.0 of the addon)

Version 1.1.0
Sept. 25, 2024
  • Added multi-region support.
  • Deprecation of the entities information enrichment for detections and events input. The entity’s information can only
    be retrieved with the entities input.
  • Added the Mitre Attack IDs and the rule's URL to the FortiNDRCloud:Detections Splunk events
Version 1.0.5
March 8, 2024
Version 1.0.4
July 30, 2023

The detections polling strategy was updated to include a configurable delay to allow them to be processed by the FortiNDR Cloud service before trying to poll them into Splunk.

Version 1.0.3
June 15, 2023
Version 1.0.2
June 15, 2023
Version 1.0.1
May 30, 2023
Version 1.0.0
May 22, 2023

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.