Skip to main content

Splunk

Download With Dependencies

Fetch events as incidents and search Splunk

This content pack runs queries on Splunk servers and fetches events from both Splunk Enterprise Security (ES) and non-ES environments.

What does this pack do?

This pack includes two integrations designed for different Splunk ES versions:

SplunkPy

The primary integration for Splunk ES versions up to 8.1, which automatically fetches notable events from Splunk along with their context data. The integration provides the analyst with comprehensive incident information directly in the XSOAR/XSIAM console.

SplunkPy v2

Designed for Splunk ES version 8.2 and higher, supporting the new Splunk Enterprise Security architecture (Findings and Investigations).

Using the commands in these integrations, you can leverage the Splunk API capabilities, such as:

  • Running SPL (Splunk Search Processing Language) queries
  • Managing events
  • Working with KV store collections (create, search, update, delete)
  • Enriching events with Asset, Identity, and Drilldown data
  • Managing indexes and submitting events
  • Bi-directional mirroring between Splunk and Cortex XSOAR

Note:
When mirroring or fetching incidents between Splunk and Cortex XSOAR, you need to map Splunk users to Cortex XSOAR users.

This content pack runs queries on Splunk servers and fetches events from both Splunk Enterprise Security (ES) and non-ES environments.

What does this pack do?

This pack includes two integrations designed for different Splunk ES versions:

SplunkPy

The primary integration for Splunk ES versions up to 8.1, which automatically fetches notable events from Splunk along with their context data. The integration provides the analyst with comprehensive incident information directly in the XSOAR/XSIAM console.

SplunkPy v2

Designed for Splunk ES version 8.2 and higher, supporting the new Splunk Enterprise Security architecture (Findings and Investigations).

Using the commands in these integrations, you can leverage the Splunk API capabilities, such as:

  • Running SPL (Splunk Search Processing Language) queries
  • Managing events
  • Working with KV store collections (create, search, update, delete)
  • Enriching events with Asset, Identity, and Drilldown data
  • Managing indexes and submitting events
  • Bi-directional mirroring between Splunk and Cortex

Note:
When mirroring or fetching incidents between Splunk and Cortex, you need to map Splunk users to Cortex XSOAR users.

PUBLISHER

PLATFORMS

Cortex XSOARCortex XSIAM

INFO

CertificationRead more
Supported ByCortex
CreatedJuly 26, 2020
Last ReleaseJune 18, 2026
WORKS WITH THE FOLLOWING INTEGRATIONS:

DISCLAIMER
By downloading or using Marketplace content, you agree to the applicable Terms of Use and End User License Agreement. Third-party content is provided by its publisher, and Palo Alto Networks does not warrant, endorse, support, or assume responsibility for content not expressly identified as owned by Palo Alto Networks.