> ## Documentation Index
> Fetch the complete documentation index at: https://developer.kyberis.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Kyberis for Splunk

> Enrich indicators from Splunk search results and alerts with Kyberis verdicts, scores, and context.

Kyberis Threat Intelligence enriches indicators of compromise — IPs, domains,
URLs, hashes, and emails — from Splunk search results and alerts with Kyberis
threat verdicts, scores, and context.

The app provides:

* the **`| kyberis`** streaming search command — batched enrichment of indicator
  fields, with CIM Threat Intelligence field mapping for Enterprise Security;
* the **Kyberis enrichment alert action** — a core Splunk alert action and
  Enterprise Security adaptive response action that enriches an alert's
  triggering results and indexes the verdicts;
* a **cross-search KV Store cache**, so repeated indicators cost zero API calls
  within a configurable TTL;
* the **`| kyberischeck`** diagnostic command and a setup page for managing named
  credential profiles in Splunk secure storage.

Everything runs on search heads. Indexers and forwarders need nothing installed
and make no outbound connections.

<Note>
  The app is published on Splunkbase as
  [Kyberis Threat Intelligence](https://splunkbase.splunk.com/app/9633). Install it
  from **Apps → Find More Apps** in Splunk Web, or download the package from the
  listing — see [Installation](/integrations/splunk/install).
</Note>

## Guides

| Document | Covers |
| - | - |
| [Installation](/integrations/splunk/install) | Requirements, install, upgrade, uninstall, search head clusters, Splunk Cloud |
| [Credential setup](/integrations/splunk/credentials) | The setup page, credential profiles, key rotation, `\| kyberischeck` |
| [Permissions and roles](/integrations/splunk/permissions) | Required capabilities, cache collection ACL, admin-only surfaces |
| [Network requirements](/integrations/splunk/network) | Egress endpoints, TLS policy, timeouts and retries, what data is sent |
| [Data handling and privacy](/integrations/splunk/privacy) | What leaves Splunk, what Kyberis retains, local persistence, controls |
| [The `\| kyberis` command](/integrations/splunk/search-command) | Syntax, options, output fields, caching, CIM mapping |
| [Alert action reference](/integrations/splunk/alert-action) | Parameters, indexed event shape, adaptive response, failure policy |
| [Troubleshooting](/integrations/splunk/troubleshooting) | Common errors, status fields, KV Store issues, logging |

## Compatibility matrix

| Component | Status |
| - | - |
| Splunk Enterprise 9.0 through 9.4, and 10.0, 10.2 and 10.4 (search heads) | Supported. These are the platform versions the Splunkbase listing declares. Verified on Splunk Enterprise 9.4, 10.0, 10.2 and 10.4. |
| Splunk Cloud Platform | Supported. The app passes AppInspect cloud vetting and installs from Splunkbase on Splunk Cloud. Verified on a Splunk Cloud 10.5 stack: self-service install, credential setup, `\| kyberischeck`, a `\| kyberis` search reaching the Kyberis API from the Splunk-hosted stack, and a KV Store cache hit on the repeat search. |
| Search head clustering | Supported. The app declares replication for its custom conf files. Verified on Splunk Enterprise 9.4 and 10.4 with a deployer and two members: the bundle push, replication of `kyberis.conf` and stored credentials, and the shared KV Store cache. After a deployer push, verify credential resolution with `\| kyberischeck` on more than one member. |
| Indexers and forwarders | Not used. The app is search-head only; commands run with `distributed=false` and the alert action runs on the search head. |
| Splunk Enterprise Security 8.x | Supported. Verified on ES 8.7: the enrichment action runs as an adaptive response action from a detection, and its indexed events populate the `Threat_Activity` dataset of the Threat Intelligence data model. |
| Splunk Enterprise Security 7.x | Reached end of support in February 2026, so ES 8.x is the validation target for this release. The adaptive response action uses the standard alert-action and Common Action Model mechanism, which ES 7.x also provides. |
| CIM | Maps to the `Threat_Activity` dataset of the Threat Intelligence data model. This data model ships with Enterprise Security itself, not the CIM add-on — the mapping is inert without ES. ES defines that dataset as `index=threat_activity`, so the alert action writes there by default on an ES instance; events indexed elsewhere keep their CIM fields but stay out of the data model. |
| Python runtime | The app declares `python.required = 3.13`. Splunk 10.2 and later run it on Python 3.13, verified on 3.13.11. Splunk 9.x and 10.0 ship no Python 3.13 runtime and run it on Python 3.9, verified on 3.9.20. |

## Support

Email [support@kyberis.ai](mailto:support@kyberis.ai).
