icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading IP Reputation App for Splunk Enterprise
SHA256 checksum (ip-reputation-app-for-splunk-enterprise_11.tgz) fb490cffe903ad9bb844b0a7732755247db9a791139654132c90ca3de6099014 SHA256 checksum (ip-reputation-app-for-splunk-enterprise_10.tgz) 9cf6d8794d3d8615597f12ebbd9b19c41b6b21f37755d363fd6a6d7712eba1dc SHA256 checksum (ip-reputation-app-for-splunk-enterprise_091.tgz) 8e4ba0e55ebbe9418a5875786d464778436bf529b46f3e48961aa40b948db0f3 SHA256 checksum (ip-reputation-app-for-splunk-enterprise_09.tgz) 0375a77c49ea2ac21beac472adbf239d729b7ce1ebe2a86c10bfac8e68ba41a8 SHA256 checksum (ip-reputation-app-for-splunk-enterprise_08.tgz) f39d4a2a7aff883f206397b2d524fe83f55619d38ad07172bf387dae9d563db2 SHA256 checksum (ip-reputation-app-for-splunk-enterprise_07.tgz) a7238d1a6b27c1f5369e2ba112feab74950526a056df039431ef3ec9e676834b SHA256 checksum (ip-reputation-app-for-splunk-enterprise_062.tgz) 024e131252212c3e86d8fe87e8017ac81577c062ed50687eb4d0490918a5aa3d SHA256 checksum (ip-reputation-app-for-splunk-enterprise_061.tgz) d807f15c3a5de2147ab36059129e4cee062897615236401be6bcd53288fa5405
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

IP Reputation App for Splunk Enterprise

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
This app allows you to enrich your IP Data with realtime threat information by contacting the Project Honey Pot database via DNS-Blacklist requests.

IP Reputation

This app allows you to enrich your IP Data with realtime threat information. Currently it's contacting the Project Honey Pot database via DNS-Blacklist requests.

Getting out value from your machine data:

  • Prioritization of Alerts/Investigation based on IP Scoring/Classification
  • Identify infected machines in your environment (you don't want to have clients who try to connect to a blacklisted IP)
  • Insight what malicious IP's are connecting to your website
  • Insight/Discovery if your current security tools help
  • Insight / KPI Numbers if new implemented configurations improve security.
  • Benchmark different Web-Application-Firewalls
  • Insight/Discovery if it would make sense to implement the http:BL apache blocking add-on on your web server
  • Find attackers who hide them as a Search Bot

Technical Details

  • adds a external lookup script feeding in clientip data, returning threatscore ( ... | lookup threatscore clientip)
  • adds a app interface with KPI Dashboard + Google Maps Dashboard Threatscore >0
  • adds automatic lookup within the App-Search of clientip fields
  • adds lookup command "lookup threatscore clientip" within the standard search app
  • adds workflow actions for clientip field (WHOIS + HoneyPot Lookup)

Make sure to obtain an http:BL Authorization Key from http://www.projecthoneypot.org/httpbl_configure.php

Feedback welcome!

Release Notes

Version 1.1
March 3, 2015

added to the lookup to give back new fields to Splunk. Now the days_since_last_activity and visitor type are available as fields.

Version 1.0
Dec. 3, 2014

Version 1.0 Update to be CIM compliant and using new Simple XML Features of 6.2

Modified Critical Network Analyzer and Threat Map Dashboard to be CIM Compliant (tag=network tag=communication
Added field inputs to both dashboards to filter data including default values
Added "How it Works" html tags for descriptions
Added new bubble chart visualization to the critical network traffic analyzer for multible dimension risk investigation

Version 0.91
Jan. 21, 2014

fixed issue with wrong threat score for search engine ip's

Version 0.9
Dec. 13, 2013

App cleanup to make it more stable
Removed the automatic lookup within the IP Reputation App to avoid to much lookups
Removed the Report Acceleration for several reports
* Changed several objects from Global to App only sharing

Version 0.8
Oct. 10, 2013

Updated the Threat Map to Support Splunk's Version 6 native maps and iplocation command as well as pie charts on the map splited by Fields. Additional some Form Inputs to ensure users better understand how to use the App, what's behind the scene, which search is running and make it customizable on the fly to change fieldnames or custom filter down of events to lookup
Update the Icons + Graphics to be compatible to Splunk's Version 6 including bar images

Version 0.7
Sept. 9, 2013
  • Created new Dashboard - Critical Network Traffic Analyzer.
    Displaying bad network communication from the last 60 minutes, designed for Firewall logs. Dashboard is in simple xml to allow easy edit and customization in case some field names need to be corrected. Dashboard displays data which has event type "check_ip".

  • based on community feedback, disabled scheduled searches for the KPI Dashboard, to avoid any performance impact if the dashboard is not used.

  • compatible with Version 6.0 - new Dashboards, Integrated Map + Form, Icons etc. in the next upcoming Version

Version 0.62
March 25, 2013
  • fixed default permission to allow using the enrichment with ... " |lookup threatscore clientip" within the default search app and other apps, too.
Version 0.61
March 22, 2013
  • Improved Navigation Bar
  • Added Info Page within the App
  • Disabled in the Lookup script the text output for the lookups
    If you want to activate it again you can activate it within the script by removing the comments - line 35,89,90,137
  • moved all config files etc. to default config to make sure further updates do not overwrite local user configurations

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.