IntelMQ
Feed automation · Austria
Read the tool profileDocumented support
Documents sending events with its TCP output bot to a configured Splunk TCP input.
An independent tool index
for incident response teams
A documented Splunk integration or output. Check any app, connector or conversion requirement before deployment.
Filter these toolsEach entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
4 tools with documented Splunk integration evidence.
Feed automation · Austria
Read the tool profileDocuments sending events with its TCP output bot to a configured Splunk TCP input.
Response coordination · France
Read the tool profileA separately installed Splunk add-on turns saved-search results into TheHive alerts, with explicit field mapping and an alert action.
Detection and monitoring · Belgium
Read the tool profileSearches and deploys rules as Splunk saved searches using a configured Splunk platform and credentials. Sigma conversion requires the separately installed Splunk backend.
Feed automation · Germany
Read the tool profileThe to_splunk operator sends JSON or raw events to a configured Splunk HTTP Event Collector using a HEC token.
A missing tool may support this feature without having been checked in this research pass.
Send a source or correction