icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Digital Guardian App for Splunk Enterprise
SHA256 checksum (digital-guardian-app-for-splunk-enterprise_203.tgz) bf5dfe3c590294c0e23b49a70a51364ec0ac0ddab497fe405c4992d122229f5a SHA256 checksum (digital-guardian-app-for-splunk-enterprise_202.tgz) 3a37d3e262b019104aeaa86e78afa0b42b7e5f7a4aacaf6d83e1ac3c2f3f04f7 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_201.tgz) e8c06fe79b747ac32cf2fd87fb6d47c1cb1af4f3a64d85d91f2bb95c6d73772b SHA256 checksum (digital-guardian-app-for-splunk-enterprise_200.tgz) e21ebfa168f48531d5ca3cc31fc8020432ad57196579a9aff2d9dcad8c873d6b SHA256 checksum (digital-guardian-app-for-splunk-enterprise_130.tgz) 3f243a6f33d381ca66a0f25ad9412d73aacc33681f6cf300c7df0673789d81df SHA256 checksum (digital-guardian-app-for-splunk-enterprise_125.tgz) cb6f875dc3c263c74635dc175de4b0977b68fcb2a25d9f709c340391cb2c7295 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_124.tgz) c24f78273c57db62ee6ef8a3f946999ab02ef1c0b9a15a5dc3dbfac7344726ef SHA256 checksum (digital-guardian-app-for-splunk-enterprise_123.tgz) 2b2901b2cd47cd3dfdf7fb4037e7ee47aaf89f6f69033e5bac80af32f8aa7491 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_122.tgz) faa4435e3a3ae851a3031ce296bd762d871fb0a4dc48920cb13929eb23f9e4ee SHA256 checksum (digital-guardian-app-for-splunk-enterprise_121.tgz) f694f01600551db75d40905a6e6c2b2090e992aa4a4effb861e97ae8e1988cbe SHA256 checksum (digital-guardian-app-for-splunk-enterprise_12.tgz) fc01c828da9e69330c646c7555a64b0d8495c3e825bb2b4012e799cd0d12aa38 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_11.tgz) 602bcd7b935c88bd983cef9e9e1717fe6518122f3a19702ddbdc949a1852725f SHA256 checksum (digital-guardian-app-for-splunk-enterprise_101.tgz) eecc6e23f35644bd02101c8175b8901700580060ae16c9a1b0deb83f81ada12e SHA256 checksum (digital-guardian-app-for-splunk-enterprise_10.tgz) bb83e3aa30ecffa90250b88a546402b53e7b08a05d0c67f221714126e75d063b
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Digital Guardian App for Splunk Enterprise

This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App works with the Digital Guardian Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

Introduction

A Splunk Application to get insight from your Digital Guardian implementation.

Installation

  1. Install the TA
  2. Move digitalguardian_web folder to your Search Head (manually or through deployment server)
  3. Restart Search Head
  4. When you go to the app for the first time, you will fill out some fields. You may need to restart after you complete setup if you see some searches not working.

Usage

Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App includes an Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

The Digital Guardian App for Splunk Enterprise includes seven dashboards that visualize Digital Guardian events and alerts with advanced abilities to drill down and filter data to pinpoint threats, investigate and respond. Dashboards include:

  • Data Classification: Show that sensitive data is effectively identified and classified
  • Alerts: Monitor policy violations, validate appropriate controls are in place and provide input into incident response process
  • Events: Monitor data leaving the enterprise by channel - Email, Print, Removable Devices and Network Uploads. Understand channel usage to establish risk level.
  • Process: Monitor process (application) access to data and identify anomalies
  • Data Egress: Monitor data movement to understand how and where data is put at risk to improve classification and controls
  • Advanced Threat Detection: Monitor malware alerts resulting from behavioral detection rules in Digital Guardian’s advanced threat module
  • Operations: Monitor operations of the Digital Guardian IT infrastructure

Release Notes

Version 2.0.3
Feb. 9, 2018

2.0.3 - 2/8/2018
* Removed extra javascript
* Fixed file permissions

Version 2.0.2
Jan. 10, 2018
Version 2.0.1
Feb. 23, 2017

2.0.1 - 2/23/2017
* Updated README

Version 2.0.0
Feb. 10, 2017

2.0.0 - 2/10/2017
* Updated for use with Splunk 6.5 and later.
* Can be used with Splunk 6.4.x, but backward compatibility before that is not guaranteed.
* Bug Fixes
* Requires Digital Guardian 7.0.0 or above

Version 1.3.0
June 4, 2015

Version 1.3.0 of the Digital Guardian App for Splunk Enterprise includes the following new changes:
* Moved lookups to TA
* Added Investigation Page
* Added Email and NTU pages
* Bug Fixes

Version 1.2.5
Jan. 15, 2015

1.2.5 - 1/15/2015
* Fixed issue with Drive Type Lookups
* Fixed issue with Data Egress Page related to Event Types

Version 1.2.4
Dec. 24, 2014

1.2.4 - 12/24/2014
* Fixed issue with Network Direction Lookup

Version 1.2.3
Dec. 24, 2014

1.2.3 - 12/24/2014
* Fixed issue with extensions search on events page for new chart includes
* Fixed base search to allow extension includes
* Backslash escaping to allow for better drilldowns.

Version 1.2.2
Dec. 23, 2014

1.2.2 - 12/23/204
* Fixed issue with base search for new charts on events page.

Version 1.2.1
Dec. 23, 2014

1.2.1 - 12/22/2014
* Fixed issue with Wildcard search changing search button name on click
* Fixed rendering issue with new charts on events page.
* Added Computer Type Lookup to application

Version 1.2
Dec. 19, 2014
Version 1.1
Nov. 23, 2014

App updated to use codes and lookups for String values across most of the app.

Version 1.0.1
Oct. 21, 2014
  • Fixed Issue with 404 Error sometimes appearing after install.
Version 1.0
Oct. 2, 2014

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.