icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Akamai Prolexic DNS GTM and SIEM API (Unofficial)
SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_132.tgz) 28570f78d1e08b3e468a38e91b030a1aefc350e7ce79f7a3262b2d8cfe62afa9 SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_131.tgz) c1713834378134714f5a21935eb0d28a9511d6736d67aa321c039a9c52515b9b SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_13.tgz) 6b95c280521e19fa7c711c4da856347c9c4885b0e4b641e9bc388d553567fd88 SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_124.tgz) bb6592828d1d7f5f6ff9b33f1d46b0c6f4ad7bc190fcce2c78fc731cdab3afb9 SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_123.tgz) 4b063e396abd52d072c44f9a4d5e94c503ab72c1327827c8a014b1496361ac6d SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_122.tgz) 3f28ba8f7622a3c34e10a7c30d0b7b43b27eda891f498ac8859cfe300b3f2458 SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_121.tgz) 979bdb462095b10e5977f0fb4df047d06c11a56b53a7ac0b5e39b4da65765af2 SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_120.tgz) cb9791f052b9633cc6d4f87fa6bf2a429fb8576679b41baa9a1f0275792df68f SHA256 checksum (akamai-prolexic-dns-gtm-and-siem-api-unofficial_110.tgz) 11af96fe1cf70cf184ff7ba8fecdaac484fce56be5cb9b696b272200e1d73a6f
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

Akamai Prolexic DNS GTM and SIEM API (Unofficial)

This app has been archived. Learn more about app archiving.
This app is NOT supported by Splunk. Please read about what that means for you here.
Overview
Details
Unofficial Splunk add on for Akamai prolexic, DNS and GTM, and SIEM API ingestion.

akamai:json_metrics -> collect Prolexic metrics using Prolexic API docs

All data is logged as JSON objects. The ingestion is performed once for every run of the input but for only new or updated metrics. For each metric the input keeps track of the last epoch timestamp logged for each metric-contract/subnet and only the recents events are logged to avoid duplicates.

akamai:json_conf -> collects GTM and DNS zones using Akamai GTM and DNS API

All data is logged as JSON objects. The ingestion is performed once for every run of the input.

akamai:json_event -> collects Prolexic events using Prolexic API.

All data is logged as JSON objects. The ingestion is performed once for every run of the input but for only new or updated events. The input calculate and saves and hash for each events (using the helper checkpoint functions from Splunk or by falling back to a local file). Only events with new hashes are logged to avoid duplicates.

akamai:json_siem collects SIEM API events.

All data is logged as JSON objects. The ingestion is performed as long as the API return at least on event or the desidered time limit is reached. The input saves the offset provided by the API so in the next run it will start to collect new events (more details in the API docs). This is the input that usually is collecting a lot of data, be careful.

Details: https://github.com/garis/Akamai-Splunk-API-integration

Special thanks to https://github.com/Pastea

Code on Github

Release Notes

Version 1.3.2
March 31, 2022

Custom action for new casemanagement input

Version 1.3.1
March 30, 2022

Add ticket info logging

Version 1.3
March 12, 2022

Tried to make the SIEM log collection running in a multi process mode. Only multi thread worked but the performance are the same (roughly 5000 events per second).

Version 1.2.4
Nov. 12, 2021

commented logging of credentails to avoid logging cleartext credentials in _internal

Version 1.2.3
Oct. 23, 2021

Workaround for stuck inputs based on the CrowdStrike add-on approach with a custom alert action.
Each input is logging Input <INPUT_NAME> has started. every time is being called.
An alert can be constructed to trigger the custom action to disable and re-enable a specific input if this string is missing from the internal logs of Splunk for a while.

Version 1.2.2
Aug. 20, 2021

Fix SIEM API decoding errors

Version 1.2.1
July 29, 2021

Correction to avoid field with the name 'source'

Version 1.2.0
July 28, 2021

Added SIEM API input.

Small bug fixes.

Version 1.1.0
July 19, 2021

1.1.0
Unofficial Splunk add on for Akamai prolexic, DNS and GTM ingestion written in Python 3.7


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk Inc. in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.