icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading FireEye Add-on for Splunk Enterprise
SHA256 checksum (fireeye-add-on-for-splunk-enterprise_311.tgz) c3b259cb46e45df025e0cee006e68a145b40c15f40a719f5bd2f77341fd13744 SHA256 checksum (fireeye-add-on-for-splunk-enterprise_309.tgz) a0f97f92e61041ab01d28cee87b091983a634b5fe2749f6e9405327917129e23 SHA256 checksum (fireeye-add-on-for-splunk-enterprise_308.tgz) 7ffe788ef2e450b783d2b59d3b62297d8ded3e059200e4807c47684d70bba0e0 SHA256 checksum (fireeye-add-on-for-splunk-enterprise_307.tgz) 94f680ac89ca808c0bf5b363bc272858bfcba076fad88cece7b4abe56842240e SHA256 checksum (fireeye-add-on-for-splunk-enterprise_306.tgz) c2cbb62710ccf9d4c651f31d5c56459f1e04b936f23f20acb61e96af6636d483 SHA256 checksum (fireeye-add-on-for-splunk-enterprise_304.tgz) 220435d48102beddc529c09ad8e8ae8205238a34f122c298ae387459d76be35d SHA256 checksum (fireeye-add-on-for-splunk-enterprise_303.tgz) 5f1a255064025e217b5e6ad7b085cd869b015b48df17dffbddffbc972782cf86
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

FireEye Add-on for Splunk Enterprise

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
FireEye TA to support the FireEye_v3 app found here: https://apps.splunk.com/app/1845/

App walk-through video:
http://youtu.be/-KBN1Xvqe6U

Supported FireEye Appliances are:
- Network Threat Prevention Platform ( NX Series )
- Email Threat Prevention Platform (EX Series)
- Forensic Analysis Platform (AX Series)
- Content Threat Prevention Platform (FX Series)
- Endpoint Threat Prevention Platform (HX Series)
- Network Forensics Platform (PX Series)
- Threat Analytics Platform (TAP)

Supported protocols and formats are:
1) JSON over HTTPS
2) XML over HTTPS
3) CEF over SYSLOG - TCP
4) CEF over SYSLOG - UDP
5) XML over SYSLOG - TCP
6) XML over SYSLOG - UDP
7) JSON over SYSLOG - TCP
8) JSON over SYSLOG - UDP
9) CSV over SYSLOG - TCP
10) CSV over SYSLOG - UDP

When you should not use this TA:
This Technology Add-on (TA) is not necessary for simple Splunk installations (e.g. Single Splunk install -- no forwarders or separate indexers)
Instead just install the app located here: https://apps.splunk.com/app/1845

When you should use this TA:
This TA supports the FireEye_v3 app. It does not contain any dashboards and should be installed on Splunk indexers while the app itself installed on the search head.

Release Notes

Version 3.1.1
Jan. 13, 2017

v3.1.1
- CM can send data to Splunk app using SYSLOG - JSON and XML Normal (confirmed operational for NX, EX, AX) - JSON Recommended over XML due to lower browser memory usage
- Parsing and displaying EX subject using fe_xml_syslog and fe_json_syslog (JSON and XML Normal verbosity not concise) - JSON is better than XML
- Moved syslog stripping for JSON to the fe_json_syslog stanzas and out of the syslog stanza
- NX visualization - Added Dest GeoIP map
- EX Analytics - Added panels for top 20 MD5 hashes and top 20 malware URLs
- Removed the syslog stanza (in props.conf) to improve overall parsing - If you need it, just re-enable it
- Removed _raw from the drop down in the dashboards - For XML and JSON, it was too much information
- Stripped the syslog header for fe_xml_syslog and changed kv_mode to XML. Commented our due to performance.
- FireEye Security Orchestrator integration and tasking Pivoting -> FSO Tasking
- fe_cef_syslog - rt now sets _time
- Hid the comprehensive dashboards

Version 3.0.9
Aug. 21, 2016

v3.0.9
Feature Requests:
- App now supports ETP (Email Threat Prevention [Cloud])
- App now supports IA Pivoting
- Created Pivoting tab
- Added IA Web Pivoting
- Added IA Email Pivoting
- Moved PX Pivoting to newly created Pivoting menu
- Added Analytics dashboards for all appliances

Bug fixes
- Fixed Wild card and ID filters in NX dashboard
- Fixed Links to product documentation

Version 3.0.8
July 20, 2016

v3.0.8
Feature requests:
- Added ability to acknowledge events and add notes (NX, EX, AX, FX, HX) (Toolbox -> Acknowledge events)
Note: Ack flags and notes in the KV Store stays intact upon app upgrades. They are lost when the app is deleted and reinstalled.
- Added ability to filter based on acknowledged events
- HX has enhanced filtering to enable easier event ack and easier downloading of redline .mans files
- Changed appliance names on analytics dashboard
- Updated VTLookup - includes working event link and autosubmit of URL if not present
- Removed Source and Sourcetype columns from all dashboards

Version 3.0.7
Aug. 23, 2015

v3.0.7
Feature requests:
- Added fields for Email CIM compliance - http://docs.splunk.com/Documentation/CIM/latest/User/Email
- Creation of Toolbox section that contains VT Lookup page - remember to delete local/data/ui/nav/default.xml and restart splunk
- Added Base64 conversion tool to Toolbox
- Added URL decoding tool to Toolbox
- Created default TAP analytics page
- Updated the Getting Started page

Bug fixes:
- json over HTTPS _time field was incorrect due to Splunk parsing the appliance-id field - Uncommented TIME_PREFIX and TIME_FORMAT fields. Thanks to Scott and Craig for noticing this issue.
- Removed bad field alias src as src for fe_cef_syslog and fe_csv_syslog
- fix_FireEye_JSON_in was missing from the TRANSFORMS-updateFireEyeIndex
- Fixed the daily analytics report. Apparently Splunk v6.2 does not like: row grouping="7"

Version 3.0.6
April 17, 2015

v3.0.6
Feature requests:
- PX integration - Can pivot based on time, SRC and DEST IP, SRC and DEST PORT
- Now supports HX 2.5 notification format - REGEX=.*:\sCEF\:\d\|fireeye\|hx\|

Version 3.0.4
Jan. 23, 2015

Matches FireEye app version 3.0.4
Fixes icon issue

Version 3.0.3
Nov. 12, 2014

v3.0.3 - First version of TA to match the FireEye_v3 app


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.