Splunk Enterprise app installation guide
Getting started
Section titled “Getting started”Install the DomainTools App on a search head or within a search head cluster. A search head is a Splunk component that handles search requests and presents results to users. This app has been tested with the recommended Splunk deployment model for apps in a clustered environment, including distributed configuration.
Review the Splunk docs on app installation and configuration in a clustered environment. See how to propagate search head cluster configuration changes.
After configuration, wait 10-15 minutes for the enrichment process to start populating the dashboards. Enrichment adds threat intelligence data to your domain observations. The app enriches new events every 5 minutes by default.
Prerequisites
Section titled “Prerequisites”- Splunk Enterprise Security (ES) or Splunk (non-ES).
- DomainTools API key access to the Iris Enrich API and Iris Investigate API — see Authentication for credential setup.
- App capabilities are still available without these, but management of Iris Investigate monitors, importing Iris Investigate and Detect terms, and ingesting Iris Investigate and Detect discoveries into Splunk won’t be available
- Firewall and networking
- Splunk must be able to reach
api.domaintools.com.
- Splunk must be able to reach
- Splunk credentials and permissions
- You need a Splunk account with
adminaccess to install and configure the app - After installation, most user functions should be available with less privileged accounts
- The user account operating the app needs the
list_storage_passwordsprivilege - You may need the admin role to access Splunk’s password storage
- You need write privileges to update internal stores; for the list of KV stores and descriptions, consult the kv store names table below
- You need a Splunk account with
- Prior Versions Uninstalled
- We recommend you uninstall any prior 3.x or 4.x versions of the DomainTools App and perform a fresh installation
- For best results, use the Splunk web UI to uninstall previous versions, and then remove any remaining DomainTools folders (for example,
/opt/splunk/etc/apps/ $ rm -rf DomainTools-App-for-Splunk/)
Install the DomainTools App
Section titled “Install the DomainTools App”Consult the Splunk Documentation for information about the Splunk platform.
The latest app is available on Splunkbase.
- For Splunk Cloud deployments, install apps on your Splunk Cloud Platform deployment using the self-service app installation process directly from Splunkbase.
- For on-prem distributed environments, deploy the DomainTools App to both indexer and search head cluster members using the standard process for deploying apps and add-ons to clusters.
Splunk Cloud
Section titled “Splunk Cloud”The DomainTools app is vetted and available for Splunk Cloud. Please follow the instructions to Install apps on your Splunk Cloud Platform deployment to add or update it on your Splunk Cloud installation.
On-premise installation
Section titled “On-premise installation”For on-premise installation, first follow the distributed installation instructions for Indexer Clusters.
Add a DomainTools API key and optional Farsight API key
Section titled “Add a DomainTools API key and optional Farsight API key”Enter your DomainTools API credentials in DT Settings → API Keys. DomainTools API credentials are available from your organization’s API administrator. Your Account Manager or DomainTools Enterprise Support enterprisesupport@domaintools.com can ensure your API key is appropriately provisioned.
Use this section to also configure proxies and SSL.
When you save new API credentials, the system prompts you to enable default saved searches.
Next steps
Section titled “Next steps”After installation, configure the app:
- Base Configuration - Configure your base search and saved searches
- Advanced Features - Enable threat feeds, alerts, and Iris Detect