Skip to main content

Splunk

Download With Dependencies

Fetch events as incidents and search Splunk

This content pack runs queries on Splunk servers and fetches events from both Splunk Enterprise Security (ES) and non-ES environments.

What does this pack do?

This pack includes two integrations designed for different Splunk ES versions:

SplunkPy

The primary integration for Splunk ES versions up to 8.1, which automatically fetches notable events from Splunk along with their context data. The integration provides the analyst with comprehensive incident information directly in the XSOAR/XSIAM console.

SplunkPy v2

Designed for Splunk ES version 8.2 and higher, supporting the new Splunk Finding Events architecture.

Using the commands in these integrations, you can leverage the Splunk API capabilities, such as:

  • Running SPL (Splunk Search Processing Language) queries
  • Managing events
  • Working with KV store collections (create, search, update, delete)
  • Enriching events with Asset, Identity, and Drilldown data
  • Managing indexes and submitting events
  • Bi-directional mirroring between Splunk and Cortex XSOAR

Note:
When mirroring or fetching incidents between Splunk and Cortex XSOAR, you need to map Splunk users to Cortex XSOAR users.

This content pack runs queries on Splunk servers and fetches events from both Splunk Enterprise Security (ES) and non-ES environments.

What does this pack do?

This pack includes two integrations designed for different Splunk ES versions:

SplunkPy

The primary integration for Splunk ES versions up to 8.1, which automatically fetches notable events from Splunk along with their context data. The integration provides the analyst with comprehensive incident information directly in the XSOAR/XSIAM console.

SplunkPy v2

Designed for Splunk ES version 8.2 and higher, supporting the new Splunk Finding Events architecture.

Using the commands in these integrations, you can leverage the Splunk API capabilities, such as:

  • Running SPL (Splunk Search Processing Language) queries
  • Managing events
  • Working with KV store collections (create, search, update, delete)
  • Enriching events with Asset, Identity, and Drilldown data
  • Managing indexes and submitting events
  • Bi-directional mirroring between Splunk and Cortex

Note:
When mirroring or fetching incidents between Splunk and Cortex, you need to map Splunk users to Cortex XSOAR users.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedJuly 26, 2020
Last ReleaseJanuary 7, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
Content packs are licensed by the Publisher identified above and subject to the Publisher’s own licensing terms. Palo Alto Networks is not liable for and does not warrant or support any content pack produced by a third-party Publisher, whether or not such packs are designated as “Palo Alto Networks-certified” or otherwise.