Splunk Enterprise app Iris Investigate
Use the Iris Investigate page to pull a domain’s current Iris Investigate profile, run guided pivots, and import domains from an Iris search hash — all within Splunk.
Domain Profile
Section titled “Domain Profile”This page pulls the current Iris Investigate details for a supplied domain for viewing directly in the Splunk environment. For information on Iris Investigate, review the Iris Investigate User Guide.
After you enter a domain and the results load, new options appear. You can add or remove the domain to the monitoring list or the allowlist. Three links also appear that open the domain directly in Iris Investigate, run a Farsight pDNS search within Splunk, and run a recent events search within Splunk.
Guided pivoting and discovery
Section titled “Guided pivoting and discovery”Hover over the gray gear icon next to a field value to show how many other domains share that exact value. If that count is below the Guided Pivot threshold (DT Settings > Configure Enrichment & Alerting), the value appears blue and hovering over the gear icon reveals a blue Pivot button you can use to explore the related domains.
Import from Iris Investigate
Section titled “Import from Iris Investigate”If you have an Iris Investigate search hash, you can import its domains and edit their monitor and allowlist statuses.
Import the list of domains from Iris into Splunk using the Export and Import functions.
- In the Iris Investigation platform, go to the Navigation Menu (3 lines) → under Search → select Import/Export.
- The subsequent dialog contains the Search Hash to export.
- From the DomainTools Splunk App, go to Investigate → Import from Iris Investigate, paste the copied hash into the Iris Search Hash field, and select Submit.
- After submitting, if the search hash has no results in the Iris Pivot Engine, there are no domains to import and Splunk shows the message “No results found”. If your account isn’t provisioned for the feature, Splunk shows “Account is not provisioned to use feature.” Otherwise, the imported domains appear in the Imported Domains table with the columns Domain, Risk Score, Proximity, Threat Profile, Threat Profile Malware, Threat Profile Phishing, Threat Profile Spam, Create Date, Monitor, and Allowlist. Edit the Monitor and Allowlist columns to manage each domain.
Recent Events
Section titled “Recent Events”Enter a domain in the Domain field and select a time range to gather data on recent events — the events in your log source where that domain appeared. Iris Investigate itself has no connection to your log source, so this view is unique to Splunk. When data is available, the table lists the log source, the URL involved, the domain name, the source IP, the destination IP, and when the event occurred.
Related resources
Section titled “Related resources”- Iris Enrich — view enrichment data and manage monitored domains and tags
- Farsight DNSDB — run a passive DNS search on a domain
- Search — run the
dtirisinvestigatecommand and other custom search commands - DT Settings — set the Guided Pivot threshold and other enrichment settings