icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading TA for Corelight
SHA256 checksum (ta-for-corelight_250.tgz) cf91c1bdf247fea1f2a850fc12c676e49fca7cb47e918c36ff781b048cf591e9 SHA256 checksum (ta-for-corelight_249.tgz) 9c79698b64f553c8f72884baa97d5657800b06e6220be42a78ddc1d7280e4eda SHA256 checksum (ta-for-corelight_248.tgz) 081bc726f4a995b5d235e19aefd00e293f24211172dc9a63ce17d3d8a69d4d69 SHA256 checksum (ta-for-corelight_247.tgz) c0b7afa792a9a588fb7818267d980767403cce8bf9654a766dd43a64904740e1 SHA256 checksum (ta-for-corelight_246.tgz) 0754ab0899a2bfe1e19c86fe891b9b858148d9e365b35a05d40ab9f609e51f77 SHA256 checksum (ta-for-corelight_245.tgz) 1bd7ecec12566eae7c84ef7a4feb4feddacb838fff3492367d6a88c4cce23414 SHA256 checksum (ta-for-corelight_221.tgz) 54d1d0d6a6b489af7fd95bab60dd154e349f712b8978115ce1abd61728b765b8 SHA256 checksum (ta-for-corelight_220.tgz) 940af8d65ebf2ee4940b120e783e919a3f17b141769ed0280d1dc904164896fe
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate


TA for Corelight

Splunk Cloud
This is the Indexer TA for the Corelight App.

Please see https://splunkbase.splunk.com/app/3884/ for more information.

Release Notes

Version 2.5.0
May 17, 2024

Please see https://splunkbase.splunk.com/app/3884/ for more information.

Version 2.4.9
Nov. 16, 2023

Version 2.4.9

  • Dashboard Enhancements
  • HTTP
    • Added dropdown filter for User Agents. Shows Top 100 only.
  • VPN Insights
    • Added dropdown filter for Inferences.
    • Fixed incorrect query for Largest Transfers Between Host Pairs Over VPN
  • Intel
    • Added dropdown filter for Incident Types.
  • Notices
    • Added a textual filter field for msg or note fields.
  • Updated Corelight Suricata IDS Alerts dashboard.
  • Extractions
  • Updated various sourcetypes to remove confusion around src/dest fields relating to id.* fields.
Version 2.4.8
July 7, 2023

Please see https://splunkbase.splunk.com/app/3884 for full details.

Version 2.4.7
June 1, 2023

Please see https://splunkbase.splunk.com/app/3884 for full details.

Version 2.4.6
March 31, 2023

= Version 2.4.6

  • Updated to CIM v5.1
  • Fixed bug in cid search command relating to icmp6 with IPv6 src_ips.
  • Updated inferences props for better extractions.
Version 2.4.5
Sept. 2, 2022
  • Fixed extractions and props.
  • Brought in line with App version.
Version 2.2.1
March 30, 2021

General bug fixes.

Version 2.2.0
Dec. 28, 2020

Corelight data natively enables Splunk Enterprise Security correlation search functionality for more than 30 correlation searches within the Certificates, Network Resolution, Network Sessions, Network Traffic, and Web data models. Corelight provides data for many Splunk Enterprise Security dashboards out of the box.
• Added parsing and dashboard visibility for Corelight Suricata logs.
• Tagged Suricata for Intrusion Detection data model functionality.
• Improved x509 log tagging for Certificate data model functionality.
• Improved conn log tagging for Network Traffic and Network Session data model functionality.
• Improved dns log tagging for Network Resolution data model functionality.
• Added DNS Hunting dashboard.
• Corrected parsing and extraction issues for corelight_x509_red log.
• Corrected issues with Home and Notices dashboards
• Updated TA-CorelightForSplunk to NOT be visible in the Splunk Web UI

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.