Add-on to support integration of Splunk with FireEye Helix Platform. Initial release provides modular inputs to retrieve alerts and incidents from your Helix instance with CIM mappings for Enterprise Security. The app includes dashboards for monitoring and exploring alerts and incidents.
This is the initial release of the FireEye Helix application. Documentation will be included in future releases.
TA-FireEye_TAP: https://github.com/pentestfail/TA-FireEye_Helix
Modified props.conf to prevent double parsing of JSON fields due to Splunk packaging utilities behavior of stripping "KV_Mode=none" required for indexed extractions.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.