Skip to main content

Requirements

  • Splunk Enterprise 9.0 through 9.4, or 10.0, 10.2 or 10.4, or Splunk Cloud Platform (see below). The app runs entirely on search heads; indexers need nothing installed.
  • Outbound HTTPS from the search head to the Kyberis API (default https://api.kyberis.ai, port 443) — see Network requirements.
  • A Kyberis API key.
  • An admin role for installation and credential setup.

Install from Splunkbase

The app is published on Splunkbase as Kyberis Threat Intelligence. In Splunk Web:
  1. Go to Apps → Find More Apps.
  2. Search for Kyberis Threat Intelligence.
  3. Select Install, and sign in with your Splunk.com account when prompted.
  4. Restart Splunk if prompted.

Install from a package file

Download the package from the Splunkbase listing, then in Splunk Web:
  1. Go to Apps → Manage Apps → Install app from file.
  2. Upload the kyberis_threat_intelligence package.
  3. Restart Splunk if prompted.
Or from the CLI:
After installation, opening the app redirects to its setup page until a credential profile is saved — see Credential setup. Verify the configuration with:

What the app installs

  • Search commands | kyberis and | kyberischeck, with search-bar help in searchbnf.conf.
  • The Kyberis enrichment alert action, available on all alerts and as an Enterprise Security adaptive response action.
  • The kyberis_ioc_cache KV Store collection — the enrichment cache, with write access admin-only (see Permissions).
  • The kyberis:threat_activity sourcetype plus an eventtype and tag pair that tag qualifying threat matches threat. On Enterprise Security the alert action writes to the threat_activity index, which is what places the events in the Enterprise Security Threat Intelligence data model.
  • A setup page for credential profiles. API keys are stored in Splunk secure storage, never in .conf files.
No scheduled searches, scripted inputs, or background jobs ship with the app.

Search head clusters

Install through the deployer as usual: place the extracted app in $SPLUNK_HOME/etc/shcluster/apps/ on the deployer and push the bundle. The app declares replication for its custom conf files (kyberis.conf, logging.conf), and the KV Store cache lives in the cluster’s KV Store. Set up credential profiles once, on any member. The API key in secure storage and the profile settings in kyberis.conf replicate to every member, so there is no per-member setup.
After the bundle push, verify credential resolution with | kyberischeck on more than one member — that confirms the conf replication landed everywhere searches will run.

Splunk Cloud

The app passes AppInspect cloud vetting and declares cloud support, so it installs on Splunk Cloud from Splunkbase like any other vetted app: go to Apps → Find More Apps, search for Kyberis Threat Intelligence, and select Install. Stacks without self-service app install need a Splunk support request to install it. After installing, verify credential resolution with | kyberischeck before pointing searches or alerts at the app. Verified on a Splunk Cloud 10.5 stack: install, credential setup, a | kyberis search reaching the Kyberis API from the Splunk-hosted stack, and a KV Store cache hit on the repeat search.
If the app does not appear in Find More Apps, check your stack version with | rest /services/server/info splunk_server=local | table version. Splunk Cloud hides apps that do not declare support for that exact version, and Cloud releases can run ahead of the versions the listing declares. Email [email protected] with the version and we will publish the declaration.

Upgrading

Upgrade in place from Apps → Manage Apps, or install the new package over the existing app; the appid stays kyberis_threat_intelligence. Local configuration — credential profiles, local/kyberis.conf overrides, and the KV Store cache — is preserved. Upgrades only replace the app’s default/ content and code.

Uninstalling

Remove the app from Splunk Web, or delete $SPLUNK_HOME/etc/apps/kyberis_threat_intelligence and restart. This also removes the credential profiles stored under the app and the cached enrichment results in the kyberis_ioc_cache collection. Events indexed by the alert action remain in whatever index they were written to.