icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Bitdefender TI Splunk App
SHA256 checksum (bitdefender-ti-splunk-app_100.tgz) f57839eb41155037ee1798f3978d0a981b0b383b1eb546ad5ecb7c70ade05698
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Bitdefender TI Splunk App

Splunk Cloud
Overview
Details
Real-time, high-confidence threat intelligence from Bitdefender integrated into Splunk.
Gain immediate visibility into novel attacks, malicious infrastructure, and active threat campaigns powered by telemetry from hundreds of millions of protected devices worldwide.

Security teams face a constant challenge: finding the real threats among countless logs and alerts. Many threat intelligence feeds are incomplete, outdated, or rely heavily on honeypots and voluntary submissions, which leaves dangerous gaps in visibility.

Bitdefender Threat Intelligence for Splunk addresses this by providing intelligence built on unique global telemetry from hundreds of millions of endpoints and networks protected across B2B and B2C environments. We detect and analyze threats in real time. When attackers create new infrastructure, deploy new malware, or exploit a vulnerability, we are among the first to know. With this Splunk integration, you can act on that knowledge immediately.

The app ingests Bitdefender’s curated and correlated threat data directly into your Splunk environment, including:

- New indicators discovered in the wild
- Correlated IoCs with attribution to actors and malware families
- Confidence and severity scores to help prioritize security tasks
- Reputation feeds updated within minutes of detection

Once in Splunk, you can use the data for lookups and correlation with your internal logs. Prebuilt dashboards such as Operational Feeds Overview, Operational Feed Details, Reputation Feed Details and Correlation Alerts give immediate context on active threats. Integration with Splunk Enterprise Security allows you to create correlation searches and alerts based on your own parameters, enabling faster incident response.

Unlike providers who depend mainly on honeypots or passive data, Bitdefender Threat Intelligence combines honeypots, scrapers, voluntary submissions, and most importantly real-world endpoint data. This ensures our feeds reflect active, ongoing attacks across industries and regions, from fileless malware in corporate networks to generic trojans targeting consumers.

Detections are featured in our feeds in under five minutes from first seen times, offering the actionable context needed to strengthen defenses, speed up investigations, and prepare effective threat hunting exercises.

Data and Intelligence

  • Real-time ingestion of IoCs (domains, IPs, URLs, file hashes, CVEs)
  • Actor and malware family attribution
  • Confidence and severity scoring for prioritization
  • Novel indicators delivered within minutes of detection

Dashboards and Analytics

  • Operational Feeds Overview for high-level visibility
  • Operational Feed Details for deep-dive investigations
  • Reputation Feed Details to check IoCs that can be correlated with internal data
  • Correlation Alerts to view triggered alerts upon IoC matches with TI data

Integration and Usability
- Supports Splunk Enterprise (v9.2.1+) and Splunk Enterprise Security
- Data format parsing for easy use in Splunk dashboards and reports
- Simple API key configuration with selectable feeds
- Quick deployment via Splunkbase or local file install

Start your free trial today and turn global threat visibility into clear, timely security action within Splunk.

Release Notes

Version 1.0.0
Sept. 16, 2025

Initial release of Bitdefender TI Splunk App


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.