Skip to main content
Kyberis ships first-party integrations for the platforms security teams already work in. Both call the same Kyberis Threat Investigator API (/v2) you use from agents and REST clients, so verdicts, scores, and evidence are identical no matter where the question is asked.

Splunk

Enrich indicators from search results with the | kyberis command, and enrich triggering results automatically with the Kyberis enrichment alert action.

Databricks

Batch-enrich indicator tables from notebooks and jobs, and investigate interactively in a Databricks App.

Choosing an integration

What both integrations have in common

  • Your API key stays in the platform’s own secret storage. Splunk stores it in storage/passwords; Databricks stores it in a secret scope. Neither integration accepts a key in configuration files, notebooks, or search syntax.
  • HTTPS only, to one destination. The only host contacted at runtime is api.kyberis.ai (or your configured base URL) on port 443. Plaintext http:// is rejected rather than warned about, and TLS verification cannot be disabled.
  • Only the indicators you select leave the platform. Neither integration scans your data on its own, and neither sends event contents, table contents, schemas, SPL, or notebook code.
  • Requests are batched. Up to 50 indicators per API call, never one call per row or event.
For the full statement in each platform, see Splunk data handling and Databricks data handling.

Where to get them

Requirements

Both integrations need a Kyberis subscription and an API key. Create one in the Kyberis dashboard under Settings → API keys, then follow the credential setup for your platform: Splunk or Databricks.