Supporting Add-on for Cortex XSOAR. This application allows a user to create incident into XSOAR from Splunk using custom alert action.
Full documentation for the add-on is available on our site (https://xsoar.pan.dev/docs/reference/articles/splunk-add-on).
This app can be installed through UI using "Manage Apps" or from the command line using the following command:
$SPLUNK_HOME/bin/splunk install app $PATH_TO_SPL/TA-Demisto.spl/
User can directly extract SPL file into $SPLUNK_HOME/etc/apps/ folder.
The new version of the app won't support verify False anymore for Cloud users due to Splunk decision regarding external requests.
The user must add a certificate in order for the add-on to work properly.
For Enterprise users, the default value of the ssl_verify configuration field will now be True.
Fixed an issue where API key contains $ sign.
The app is now supported in XSOAR v8.
This version was created using Splunk add-on builder version 4.1.0, therefore it does not longer supports python2, as well as Splunk versions lower than 8.0
Changes made from v3.0.8:
- Additional parameter (timeout) was added, it controls the timeout of the incident creation request.
- More logging in case of error added.
Fixed an issue where incidents could not be created successfully with SSL certificates.
Fixed an issue where ad-hoc incidents from Splunk ES were not created successfully.
Fixed an issue where incidents were not created successfully from notable events.
Added an option to input custom fields with values that contain commas/colons. The values in this case should be wrapped with apostrophes, quotation marks, backticks, parenthesis or curly brackets.
Support multiple certificates for multiple servers
Stability enhancement for supporting splunk cloud compatibility.
New version of Demisto add-on for Splunk, compatible with python 2 and 3.
The upgrade requires reconfiguration of the add-on.
Regex improvements
-- App Certification Failure Fixed - Batch Stanza
-- Timezone changes while creating Incident
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.