Splunk Enterprise app Enrichment Explorer
The Enrichment Explorer provides DomainTools intelligence data for domains observed in your network from the app’s cache, and lets you search and filter the results. This page covers both the Enrichment Explorer and the Enrichment Dashboard.
Enrichment Explorer
Section titled “Enrichment Explorer”Filters
Section titled “Filters”- Domain
- Age Less Than (days)
- Last Enriched
- Choose between Splunk’s time ranges. Review Specify Time Ranges for more information.
- Risk Score Greater Than
- Enter a value between 0-100
- Threat Type
- No filter
- Any Threat Type
- Malware
- Phishing
- Spam
- Not a Threat
- Show Monitored Domains Only
- Changes the dataset to only display domains that fall into a monitored list
- Display
- Sets the DomainTools KV Store Explorer table to Summary (the important fields) or All Fields (the entirety of the available data for domains).
Enrich Explorer Visualization
Section titled “Enrich Explorer Visualization”Available in the enrichment explorer is a pie chart that displays the frequency of data points of a chosen field type.
Enrich Explorer Visualization Types:
- Create Date
- Expiration Date
- IP Address
- IP ASN
- IP Country Code
- IP ISP
- MX Domain
- MX Host
- MX IP
- Name Server
- Name Server Host
- Name Server IP
- Redirect URL
- Registrant Name
- Registrant organization
- Registrar
- Website Title
- TLD
- SSL Common Name
- SSL Duration
- SSL Issuer Common Name
- SSL Not Before
- SSL Not After
- SSL Subject
- SSL Org
- SSL Hash
- Adsense Code
- GA4 code
- Yandex Code
- Facebook Code
- GTM code
- Matomo code
DomainTools KV Store Explorer
Section titled “DomainTools KV Store Explorer”The KV Store Explorer is a table that displays the results of the search filters chosen at the top of the page. By default the summarized view is displayed. Select the Monitor field to add or remove a domain from your monitoring list. Select the Allowlist field to add or remove a domain from your allowlist.
Summarized KV store explorer table:
| Domain Name | Profile | Age | Active Status | Overall Risk Score | Last Enriched DateTime | First Seen | Proximity Score | Threat Type | Threat Profile Malware | Threat Profile Phishing | Threat Profile Spam | Observed in Logs | IPs | IP ISPs | Name Server Domains | Threat Profile Evidence | Website Title | Monitor | Allowlist |
|---|
Refresh Domains
Section titled “Refresh Domains”If a domain appears to have outdated information, you can choose to refresh the KV store by selecting the green Refresh button. Refreshing may take some time to display current results.
Enrichment Dashboard
Section titled “Enrichment Dashboard”The Enrichment Dashboard visualizes and lists information in a set of panels for frequently encountered domain attributes. Use each panel to search, set the time period of the search, and click through to bring up Splunk’s search for more information. Hover over a data set to open the query in search, export it, inspect the job, force a refresh of the data, and view how long ago the last enrichment refresh happened.
The last enriched field uses Splunk’s time ranges. Review Specify Time Ranges for more information.
Top Registrars
Section titled “Top Registrars”This section displays the most common registrars, including the amount of times and percentage of time that the registrar is seen in the enrichment data.
Filters used:
- Registrar Name
- Last Enriched
The data appears in both a bar graph and a table. Hover over a bar graph entry to see the exact percentage.
Top Registrars table:
| Registrar Name | count | percent |
|---|
Top NameServers
Section titled “Top NameServers”This section displays the top nameservers, including the amount of times and percentage of time that a nameserver is seen in the enrichment data.
Filters:
- Nameserver
- Last Enriched
The data appears in both a bar graph and a table. Hover over a bar graph entry to see the exact percentage.
Top Nameservers table:
| NameServer | count | percent |
|---|
Top ISPs
Section titled “Top ISPs”This section displays the top ISPs, including how many unique nameservers and registrars are associated.
Filters:
- ISP Name
- Last Enriched
Top ISPs table:
| ISP | Related Nameservers | Total Unique Nameservers | Related Registrars | Total Unique Registrars |
|---|
Top IP Addresses
Section titled “Top IP Addresses”This section displays the top IP addresses, including the amount of times and percentage of time that an IP address is seen in the enrichment data.
Filters:
- IP Address
- Last Enriched
Top IP Addresses table:
| IP Address | count | percent |
|---|
Top ASNs
Section titled “Top ASNs”This section displays the top IP ASNs, including the amount of times and percentage of time that an ASN is seen in the enrichment data.
Filters:
- ASN
- Last Enriched
| ASN (Autonomous System Numbers) | count | percent |
|---|
Top Expired SSL Certificate
Section titled “Top Expired SSL Certificate”Displays when an SSL certificate expired, the provider, what domains, and the frequency.
Filters:
- SSL Certificate Providers
- Domain Name
- Last Enriched
Top Expired SSL Certificate table:
| SSL Expire Date | Total SSL Certificate Providers | Total Domains | count | percent |
|---|
Related resources
Section titled “Related resources”- Iris Enrich — the dashboards that visualize this enrichment data
- Iris Investigate — pull a full profile for a domain found in the explorer
- DT Settings — configure enrichment, caching, and the app cache retention period