Requirements
- Splunk Enterprise 9.0 through 9.4, or 10.0, 10.2 or 10.4, or Splunk Cloud Platform (see below). The app runs entirely on search heads; indexers need nothing installed.
- Outbound HTTPS from the search head to the Kyberis API (default
https://api.kyberis.ai, port 443) — see Network requirements. - A Kyberis API key.
- An admin role for installation and credential setup.
Install from Splunkbase
The app is published on Splunkbase as Kyberis Threat Intelligence. In Splunk Web:- Go to Apps → Find More Apps.
- Search for Kyberis Threat Intelligence.
- Select Install, and sign in with your Splunk.com account when prompted.
- Restart Splunk if prompted.
Install from a package file
Download the package from the Splunkbase listing, then in Splunk Web:- Go to Apps → Manage Apps → Install app from file.
- Upload the
kyberis_threat_intelligencepackage. - Restart Splunk if prompted.
What the app installs
- Search commands
| kyberisand| kyberischeck, with search-bar help insearchbnf.conf. - The Kyberis enrichment alert action, available on all alerts and as an Enterprise Security adaptive response action.
- The
kyberis_ioc_cacheKV Store collection — the enrichment cache, with write access admin-only (see Permissions). - The
kyberis:threat_activitysourcetype plus an eventtype and tag pair that tag qualifying threat matchesthreat. On Enterprise Security the alert action writes to thethreat_activityindex, which is what places the events in the Enterprise Security Threat Intelligence data model. - A setup page for credential profiles. API keys are stored in Splunk secure
storage, never in
.conffiles.
Search head clusters
Install through the deployer as usual: place the extracted app in$SPLUNK_HOME/etc/shcluster/apps/ on the deployer and push the bundle. The app
declares replication for its custom conf files (kyberis.conf,
logging.conf), and the KV Store cache lives in the cluster’s KV Store.
Set up credential profiles once, on any member. The API key in secure storage
and the profile settings in kyberis.conf replicate to every member, so there
is no per-member setup.
After the bundle push, verify credential resolution with
| kyberischeck on more
than one member — that confirms the conf replication landed everywhere searches
will run.Splunk Cloud
The app passes AppInspect cloud vetting and declares cloud support, so it installs on Splunk Cloud from Splunkbase like any other vetted app: go to Apps → Find More Apps, search for Kyberis Threat Intelligence, and select Install. Stacks without self-service app install need a Splunk support request to install it. After installing, verify credential resolution with| kyberischeck before
pointing searches or alerts at the app.
Verified on a Splunk Cloud 10.5 stack: install, credential setup, a
| kyberis search reaching the Kyberis API from the Splunk-hosted stack, and
a KV Store cache hit on the repeat search.
If the app does not appear in Find More Apps, check your stack version with
| rest /services/server/info splunk_server=local | table version. Splunk Cloud
hides apps that do not declare support for that exact version, and Cloud
releases can run ahead of the versions the listing declares. Email
[email protected] with the version and we will
publish the declaration.Upgrading
Upgrade in place from Apps → Manage Apps, or install the new package over the existing app; the appid stayskyberis_threat_intelligence. Local configuration — credential profiles,
local/kyberis.conf overrides, and the KV Store cache — is preserved. Upgrades
only replace the app’s default/ content and code.
Uninstalling
Remove the app from Splunk Web, or delete$SPLUNK_HOME/etc/apps/kyberis_threat_intelligence and restart. This also
removes the credential profiles stored under the app and the cached enrichment
results in the kyberis_ioc_cache collection. Events indexed by the alert
action remain in whatever index they were written to..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)