> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Install the Splunk app

> Requirements, install and upgrade steps, search head clusters, and Splunk Cloud.

## Requirements

* Splunk Enterprise 9.0 through 9.4, or 10.0, 10.2 or 10.4, or Splunk Cloud Platform (see
  below). The app runs entirely on search heads; indexers need nothing installed.
* Outbound HTTPS from the search head to the Kyberis API (default
  `https://api.kyberis.ai`, port 443) — see
  [Network requirements](/integrations/splunk/network).
* A Kyberis API key.
* An admin role for installation and credential setup.

## Install from Splunkbase

The app is published on Splunkbase as
[Kyberis Threat Intelligence](https://splunkbase.splunk.com/app/9633).

In Splunk Web:

1. Go to **Apps → Find More Apps**.
2. Search for **Kyberis Threat Intelligence**.
3. Select **Install**, and sign in with your Splunk.com account when prompted.
4. Restart Splunk if prompted.

## Install from a package file

Download the package from the
[Splunkbase listing](https://splunkbase.splunk.com/app/9633), then in Splunk Web:

1. Go to **Apps → Manage Apps → Install app from file**.
2. Upload the `kyberis_threat_intelligence` package.
3. Restart Splunk if prompted.

Or from the CLI:

```bash theme={null}
$SPLUNK_HOME/bin/splunk install app kyberis_threat_intelligence-<version>.tar.gz
$SPLUNK_HOME/bin/splunk restart
```

After installation, opening the app redirects to its setup page until a
credential profile is saved — see
[Credential setup](/integrations/splunk/credentials). Verify the configuration
with:

```
| kyberischeck
```

## What the app installs

* Search commands `| kyberis` and `| kyberischeck`, with search-bar help in
  `searchbnf.conf`.
* The **Kyberis enrichment** alert action, available on all alerts and as an
  Enterprise Security adaptive response action.
* The `kyberis_ioc_cache` KV Store collection — the enrichment cache, with
  write access admin-only (see
  [Permissions](/integrations/splunk/permissions)).
* The `kyberis:threat_activity` sourcetype plus an eventtype and tag pair that
  tag qualifying threat matches `threat`. On Enterprise Security the alert
  action writes to the `threat_activity` index, which is what places the events
  in the Enterprise Security Threat Intelligence data model.
* A setup page for credential profiles. API keys are stored in Splunk secure
  storage, never in `.conf` files.

No scheduled searches, scripted inputs, or background jobs ship with the app.

## Search head clusters

Install through the deployer as usual: place the extracted app in
`$SPLUNK_HOME/etc/shcluster/apps/` on the deployer and push the bundle. The app
declares replication for its custom conf files (`kyberis.conf`,
`logging.conf`), and the KV Store cache lives in the cluster's KV Store.

Set up credential profiles once, on any member. The API key in secure storage
and the profile settings in `kyberis.conf` replicate to every member, so there
is no per-member setup.

<Note>
  After the bundle push, verify credential resolution with `| kyberischeck` on more
  than one member — that confirms the conf replication landed everywhere searches
  will run.
</Note>

## Splunk Cloud

The app passes AppInspect cloud vetting and declares cloud support, so it
installs on Splunk Cloud from Splunkbase like any other vetted app: go to
**Apps → Find More Apps**, search for **Kyberis Threat Intelligence**, and
select **Install**. Stacks without self-service app install need a Splunk
support request to install it.

After installing, verify credential resolution with `| kyberischeck` before
pointing searches or alerts at the app.

Verified on a Splunk Cloud 10.5 stack: install, credential setup, a
`| kyberis` search reaching the Kyberis API from the Splunk-hosted stack, and
a KV Store cache hit on the repeat search.

<Note>
  If the app does not appear in **Find More Apps**, check your stack version with
  `| rest /services/server/info splunk_server=local | table version`. Splunk Cloud
  hides apps that do not declare support for that exact version, and Cloud
  releases can run ahead of the versions the listing declares. Email
  [support@kyberis.ai](mailto:support@kyberis.ai) with the version and we will
  publish the declaration.
</Note>

## Upgrading

Upgrade in place from **Apps → Manage Apps**, or install the new package over
the existing app; the appid stays `kyberis_threat_intelligence`. Local configuration — credential profiles,
`local/kyberis.conf` overrides, and the KV Store cache — is preserved. Upgrades
only replace the app's `default/` content and code.

## Uninstalling

Remove the app from Splunk Web, or delete
`$SPLUNK_HOME/etc/apps/kyberis_threat_intelligence` and restart. This also
removes the credential profiles stored under the app and the cached enrichment
results in the `kyberis_ioc_cache` collection. Events indexed by the alert
action remain in whatever index they were written to.
