The Mandiant Digital Threat Monitoring Add-on for Splunk provides a seamless integration to ingest and visualize alerts from the Mandiant Digital Threat Monitoring service. This add-on allows users to configure multiple data inputs, to periodically fetch alerts. A dedicated dashboard offers a comprehensive overview of the ingested alerts, enabling security analysts to quickly identify and act on potential threats.
Splunk Version | OS |
---|---|
9.2, 9.3, 9,4 | Linux, Windows |
Global configurations for the add-on can be accessed by navigating to the add-on's configuration page.
If your Splunk instance requires a proxy to connect to external services, you can configure the proxy settings in this section. You will need to provide the proxy host, port, and credentials if required.
Configure the logging level for the add-on to control the amount of information that is written to the logs. Available levels are typically DEBUG
, INFO
, WARNING
, ERROR
, and CRITICAL
. The default is usually INFO
.
This section allows you to configure the global settings for the add-on's.
dtm
.doc.payment_card
, doc.service_account
, and topics
are not ingested. Check this box to enable the ingestion of this sensitive information.To start ingesting alerts, you need to configure one or more inputs. From the add-on's "Inputs" page, click on Create New Input to open the "Add DTM Alerts" modal.
default
.The add-on includes a pre-built dashboard to visualize and analyze the ingested alerts.
The dashboard provides a high-level overview of the alerts over the last 7 days. It includes two main panels:
Below the overview charts, there is a detailed table of the latest alerts. The table provides the following information for each alert:
Compromised Credentials
, Leaked Web Service Credentials
).Compromised Credentials
, Deep & Dark Web
).Low
, High
).For any questions, issues, or feature requests, please contact our support team at: contact@virustotal.com
Q: Where can I find my Mandiant API credentials to configure a Global Account?
A: You can find your Mandiant API credentials in your Mandiant Digital Threat Monitoring portal under the API settings section.
Q: What is the M-Score?
A: The M-Score is Mandiant's proprietary risk score that helps to prioritize alerts. A higher score indicates a higher risk.
Q: Can I create multiple inputs with different configurations?
A: Yes, you can create as many inputs as you need, each with its own set of filters for M-Score, Alert Status, and Alert Types, and specify a different index for each if required.
Q: Why are some fields like doc.payment_card
not appearing in my events?
A: By default, sensitive information is not indexed to protect privacy and reduce noise. You can enable the ingestion of sensitive fields in the "Settings" under the add-on's configuration page.
Q: How can I customize the dashboard?
A: You can clone the provided dashboard and then edit the cloned version to add, remove, or modify the panels and visualizations to fit your specific needs.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.