Summary
This is the initial release of a new modular input app designed to collect and manage Indicators of Compromise (IoCs) using KV Store instead of traditional indexing.
Key Benefits
Cost-Efficient Data Management
By storing IoCs in the KV Store rather than indexing them, the app significantly reduces storage costs—ideal for handling high volumes of threat intelligence data.
Optimized for Performance
KV Store enables faster lookups and updates, improving operational efficiency in environments where real-time response and enrichment are critical.
Cleaner Architecture
Designed for Splunk Cloud environments with improved separation of storage and search logic.
Replaces Legacy App
This version is intended to replace the legacy app that relied on indexed data. While the legacy version will continue to receive critical patches, this KV Store–based app is the recommended path forward for all new deployments.
We encourage all users to migrate to this version to take advantage of the performance and cost benefits.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.