The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App works with this Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. This Add-on is designed for Digital Guardian 6.2.2 and above. For use with previous versions please contact Digital Guardian.
None
Version 1.1.2 of the TA for Digital Guardian is compatible with:
TA for Digital Guardian includes the following new features:
Version 1.1.2 of the TA for Digital Guardian fixes the following issues:
- Fixed Bug in props.conf
Version 1.1.1 of the TA for Digital Guardian fixes the following issues:
- Updated EventGen Samples
- Updated Documentation
- Removed hidden files
Version 1.1 of the TA for Digital Guardian fixes the following issues:
Questions and Answers
Access questions and answers about the TA for Digital Guardian at http://answers.splunk.com/answers/app/1878
Support
Support URL: https://digitalguardian.force.com/support/login
How to get support: via above support portal URL. Login is required for Digital Guardian customers; customers who do not have a support login may apply for one at support@digitalguardian.com
Support hours: 24/7
Observed holidays: Closed on major US holidays.
Response: all cases submitted will be confirmed via email; response time based on severity
Cases are tracked in the salesforce.com system
TA for Digital Guardian supports the following server platforms in the versions supported by Splunk Enterprise:
To function properly, TA for Digital Guardian requires the following software:
Because this add-on runs on Splunk Enterprise, all of the Splunk Enterprise system requirements apply.
Download the TA for Digital Guardian at https://apps.splunk.com/app/1878/.
To install and configure this app on your supported platform, follow these steps:
Follow these steps to install the app in a single server instance of Splunk Enterprise:
Install to search head
Install to indexers
Install to forwarders
Configuration Steps are in Installation Instructions.
Digital Guardian offers security’s most technologically advanced endpoint agent. Only Digital Guardian ends data theft by protecting sensitive data from skilled insiders and persistent outside attackers.
The Digital Guardian App for Splunk Enterprise lets customers understand risks to sensitive data across the enterprise from insider and outsider threats and respond appropriately. Users can improve incident response and investigation times by leveraging Splunk’s enterprise search capabilities across Digital Guardian event and alert data. The App includes an Add-on which brings Digital Guardian events and alerts into Splunk Enterprise. The Add-on is designed for Digital Guardian 6.2.2 and above. For use with previous versions please contact Digital Guardian.
The Digital Guardian App for Splunk Enterprise includes seven dashboards that visualize Digital Guardian events and alerts with advanced abilities to drill down and filter data to pinpoint threats, investigate and respond. Dashboards include:
These data types support the following Common Information Model data models:
The TA for Digital Guardian contains 1 lookup file.
severity_lookup
Translates Severity Code to Human Readable Name.
key,value
1,Informational
2,Low
3,Medium
4,High
5,Critical
2.0.3 - 2/8/2018
* Updated file permissions
Version 1.3.0 TA for Digital Guardian includes the following new features:
- Moved Lookup Tables from App to TA (computer_type_lookup, dg_protocol_lookup, drive_type_lookup, email_recepient_type_lookup, file_encryption_lookup, network_direction_lookup, operations_lookup, rule_action_type_lookup, scanvalue_lookup)
- Added Custom Event functionality for Alerts
- Update Version Number to match digitalguardian_web
Version 1.1.2 of the TA for Digital Guardian fixes the following issues:
- Fixed Bug in props.conf
Version 1.1.1 of the TA for Digital Guardian fixes the following issues:
- Updated EventGen Samples
- Updated Documentation
- Removed hidden files
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.