> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Platform integrations

> Bring Kyberis enrichment and investigation into Splunk and Databricks, where your detection and security data already lives.

Kyberis ships first-party integrations for the platforms security teams already
work in. Both call the same Kyberis Threat Investigator API (`/v2`) you use from
agents and REST clients, so verdicts, scores, and evidence are identical no
matter where the question is asked.

<CardGroup cols={2}>
  <Card title="Splunk" icon="magnifying-glass-chart" href="/integrations/splunk/overview">
    Enrich indicators from search results with the `| kyberis` command, and enrich
    triggering results automatically with the Kyberis enrichment alert action.
  </Card>

  <Card title="Databricks" icon="database" href="/integrations/databricks/overview">
    Batch-enrich indicator tables from notebooks and jobs, and investigate
    interactively in a Databricks App.
  </Card>
</CardGroup>

## Choosing an integration

| You want to | Use |
| - | - |
| Enrich indicators inline in an SPL search | [The `\| kyberis` command](/integrations/splunk/search-command) |
| Enrich an alert's triggering results and index the verdicts | [The Kyberis enrichment alert action](/integrations/splunk/alert-action) |
| Enrich a Delta table of indicators on a schedule | [Databricks notebooks and jobs](/integrations/databricks/install) |
| Investigate indicators interactively without writing SPL or Python | [The Databricks App](/integrations/databricks/install#3-databricks-app) |
| Call Kyberis from an agent or your own code | [Install Kyberis in your agent](/install/overview) or the [API reference](/api-reference/introduction) |

## What both integrations have in common

* **Your API key stays in the platform's own secret storage.** Splunk stores it
  in `storage/passwords`; Databricks stores it in a secret scope. Neither
  integration accepts a key in configuration files, notebooks, or search syntax.
* **HTTPS only, to one destination.** The only host contacted at runtime is
  `api.kyberis.ai` (or your configured base URL) on port 443. Plaintext `http://`
  is rejected rather than warned about, and TLS verification cannot be disabled.
* **Only the indicators you select leave the platform.** Neither integration
  scans your data on its own, and neither sends event contents, table contents,
  schemas, SPL, or notebook code.
* **Requests are batched.** Up to 50 indicators per API call, never one call per
  row or event.

For the full statement in each platform, see
[Splunk data handling](/integrations/splunk/privacy) and
[Databricks data handling](/integrations/databricks/privacy).

## Where to get them

| Integration | Listing |
| - | - |
| Splunk | [Kyberis Threat Intelligence on Splunkbase](https://splunkbase.splunk.com/app/9633) |
| Databricks | [Kyberis Threat Intelligence for Databricks on Databricks Marketplace](https://marketplace.databricks.com/details/3205ecb2-64eb-4baf-8207-b97cd90a18d4/Kyberis_Kyberis-Threat-Intelligence-for-Databricks) |

## Requirements

Both integrations need a Kyberis subscription and an API key. Create one in the
Kyberis dashboard under **Settings → API keys**, then follow the credential
setup for your platform:
[Splunk](/integrations/splunk/credentials) or
[Databricks](/integrations/databricks/credentials).
