/v2) you use from
agents and REST clients, so verdicts, scores, and evidence are identical no
matter where the question is asked.
Splunk
Enrich indicators from search results with the
| kyberis command, and enrich
triggering results automatically with the Kyberis enrichment alert action.Databricks
Batch-enrich indicator tables from notebooks and jobs, and investigate
interactively in a Databricks App.
Choosing an integration
What both integrations have in common
- Your API key stays in the platform’s own secret storage. Splunk stores it
in
storage/passwords; Databricks stores it in a secret scope. Neither integration accepts a key in configuration files, notebooks, or search syntax. - HTTPS only, to one destination. The only host contacted at runtime is
api.kyberis.ai(or your configured base URL) on port 443. Plaintexthttp://is rejected rather than warned about, and TLS verification cannot be disabled. - Only the indicators you select leave the platform. Neither integration scans your data on its own, and neither sends event contents, table contents, schemas, SPL, or notebook code.
- Requests are batched. Up to 50 indicators per API call, never one call per row or event.
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)