The Trend Micro DDI Splunk Add-On is designed to enhance your Splunk deployment by providing robust parsing capabilities for Trend Micro Deep Discovery Inspector (DDI) logs. This add-on focuses solely on parsing already ingested logs, ensuring that your security data is accurately extracted, categorized, and ready for analysis. By aligning with Splunk's Common Information Model (CIM), it facilitates seamless integration with other Splunk apps and dashboards, enabling efficient security monitoring and incident response.
Purpose of the Add-On:
After extensive research into existing Splunk add-ons for parsing Trend Micro DDI logs, no suitable solutions were found that met the specific needs for comprehensive parsing and log categorization. Consequently, this add-on was developed to fill that gap, providing a tailored solution for organizations leveraging Trend Micro DDI with Splunk.
To offer a foundation for future enhancements, including dashboard integrations and advanced analytics.
How It Works:
Note: This add-on is a work in progress. While it provides essential parsing and categorization functionalities, it is not yet perfect. Ongoing development is planned to refine existing features and introduce new capabilities, such as dedicated dashboards for comprehensive data visualization.
Before installing the Trend Micro DDI Splunk Add-On, ensure that the following prerequisites are met:
trendmicro:ddi
The Trend Micro DDI Splunk Add-On was developed by:
For support and assistance with the Trend Micro DDI Splunk Add-On, please contact:
Support Hours: Sunday to Thursday, 9:00 AM to 5:00 PM UTC+3
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.