icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Digital Guardian App for Splunk Enterprise
SHA256 checksum (digital-guardian-app-for-splunk-enterprise_203.tgz) ff2af3be8331a3edd607efe236ee74d678c974caa3aae327513dbf8b9666a386 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_202.tgz) 83afe59bbfe1ce625c2f79e8443e7a866c65b985bc1bc6cd5927c62b24ee4682 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_201.tgz) 76fd7c63b692dfceb11d8ae3274da26c20861dc5858a2a3f7eda2f9d620f21d8 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_200.tgz) fd116b7648dc1135259ff3c6a17d57471d00877b66d5346f073ea2c4d04df0f7 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_130.tgz) 807b95926e959cdff167bbd9b5a0531141aa51b460549b1476c7bd6ad0bb66ae SHA256 checksum (digital-guardian-app-for-splunk-enterprise_125.tgz) 64a37233fd22d53a8e7f16449e600b7a2643f058d66638c60cb9acb00d55cd0c SHA256 checksum (digital-guardian-app-for-splunk-enterprise_124.tgz) 9a3798f884558da1ca719f2319f74805b93b87ceb733de7ae2ea6b9b6f891438 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_123.tgz) 8fdaf9d7b7852f6989506ed9ff25834fe3cae17a30e9a98fbb862fff944052ca SHA256 checksum (digital-guardian-app-for-splunk-enterprise_122.tgz) 6ccc95ac0098509f5cb61a5a5d560adb46690cb0679ac723ac08c813319c9cd8 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_121.tgz) 88aff21590624a79dbeea730daa837e3b8ac4c065ecea0d571a9c264447894b7 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_12.tgz) b65c50db6a4ad5110e1200f4cdbee531f00fa950bb564e7d1ab345e557e9f4cf SHA256 checksum (digital-guardian-app-for-splunk-enterprise_11.tgz) 66a0599a88a593a4bb593fe25cf63ef41b4cc90cb6d64b5bed3c353e9ae7f2e0 SHA256 checksum (digital-guardian-app-for-splunk-enterprise_101.tgz) 8f96a415f04b82d1e0fdb000a586a8d9c68772ec89d1f008729df1755b90d79c SHA256 checksum (digital-guardian-app-for-splunk-enterprise_10.tgz) baf4ed843f60d153add1c031d1719b35e71d6e7de415af24e22bd33853825a68
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Digital Guardian App for Splunk Enterprise

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App works with the Digital Guardian Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

Introduction

A Splunk Application to get insight from your Digital Guardian implementation.

Installation

  1. Install the TA
  2. Move digitalguardian_web folder to your Search Head (manually or through deployment server)
  3. Restart Search Head
  4. When you go to the app for the first time, you will fill out some fields. You may need to restart after you complete setup if you see some searches not working.

Usage

Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.

The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App includes an Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 7.0.0 and above. For use with previous versions please contact Digital Guardian.

The Digital Guardian App for Splunk Enterprise includes seven dashboards that visualize Digital Guardian events and alerts with advanced abilities to drill down and filter data to pinpoint threats, investigate and respond. Dashboards include:

  • Data Classification: Show that sensitive data is effectively identified and classified
  • Alerts: Monitor policy violations, validate appropriate controls are in place and provide input into incident response process
  • Events: Monitor data leaving the enterprise by channel - Email, Print, Removable Devices and Network Uploads. Understand channel usage to establish risk level.
  • Process: Monitor process (application) access to data and identify anomalies
  • Data Egress: Monitor data movement to understand how and where data is put at risk to improve classification and controls
  • Advanced Threat Detection: Monitor malware alerts resulting from behavioral detection rules in Digital Guardian’s advanced threat module
  • Operations: Monitor operations of the Digital Guardian IT infrastructure

Release Notes

Version 2.0.3
Feb. 9, 2018

2.0.3 - 2/8/2018
* Removed extra javascript
* Fixed file permissions

Version 2.0.2
Jan. 10, 2018
Version 2.0.1
Feb. 23, 2017

2.0.1 - 2/23/2017
* Updated README

Version 2.0.0
Feb. 10, 2017

2.0.0 - 2/10/2017
* Updated for use with Splunk 6.5 and later.
* Can be used with Splunk 6.4.x, but backward compatibility before that is not guaranteed.
* Bug Fixes
* Requires Digital Guardian 7.0.0 or above

Version 1.3.0
June 4, 2015

Version 1.3.0 of the Digital Guardian App for Splunk Enterprise includes the following new changes:
* Moved lookups to TA
* Added Investigation Page
* Added Email and NTU pages
* Bug Fixes

Version 1.2.5
Jan. 15, 2015

1.2.5 - 1/15/2015
* Fixed issue with Drive Type Lookups
* Fixed issue with Data Egress Page related to Event Types

Version 1.2.4
Dec. 24, 2014

1.2.4 - 12/24/2014
* Fixed issue with Network Direction Lookup

Version 1.2.3
Dec. 24, 2014

1.2.3 - 12/24/2014
* Fixed issue with extensions search on events page for new chart includes
* Fixed base search to allow extension includes
* Backslash escaping to allow for better drilldowns.

Version 1.2.2
Dec. 23, 2014

1.2.2 - 12/23/204
* Fixed issue with base search for new charts on events page.

Version 1.2.1
Dec. 23, 2014

1.2.1 - 12/22/2014
* Fixed issue with Wildcard search changing search button name on click
* Fixed rendering issue with new charts on events page.
* Added Computer Type Lookup to application

Version 1.2
Dec. 19, 2014
Version 1.1
Nov. 23, 2014

App updated to use codes and lookups for String values across most of the app.

Version 1.0.1
Oct. 21, 2014
  • Fixed Issue with 404 Error sometimes appearing after install.
Version 1.0
Oct. 2, 2014

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.