Xpanse's Technical Add-on for Splunk allows you to consume and access Issues Updates, Assets, and Services data through Splunk. You can configure your own Expander data as a Splunk data input, configure the add-on to use a proxy, search your Expander data through the Splunk UI using Splunk data queries, and more.
This allows you to:
- Ease-of-use for data querying in a commonly-used SIEM
- Centralize alerting
- Have a single source-of-truth for security-related data
- Correlate Expander Issues Updates data to internal events tracked in Splunk
- Create custom reporting, dashboards, and visualizations
- Gain context for IPs, Domains, Certificates, and related Issues observed on your network perimeter