Splunk Search
runZero integrates with Splunk through a dedicated Splunk Addon that is compatible with Splunk 7, Splunk 8, and Splunk Cloud. The add-on pulls new or updated hosts into a Splunk index, where you can analyze, visualize, and monitor them.
The add-on uses the Splunk API from the runZero Network Discovery platform. It syncs assets into Splunk with multiple inputs, global API key management, and an optional search filter for each input. For example, you can track new assets as one input and SMBv1-enabled assets as another.
To set up the add-on, you need an Export API or Organization API key, which you can generate from your Organization page in the runZero Console. For an overview of the runZero APIs, see the API documentation.
Get the runZero add-on for Splunk
- Sign in to Splunk.
- Go to Find More Apps.
- Search for
runZero Network Discovery. - Install the add-on for runZero.
- Splunk prompts you to sign in again. After you log back in, the add-on is installed and you can open the runZero Asset Sync app. Splunk might also prompt you to restart your server.
Asset sync modes
The add-on has two asset sync modes: New Assets Only and All Updated Assets. You can export the assets newly discovered or updated since the last poll, in a sync-friendly format for Splunk. When you pull data into Splunk, you can use the same Asset Sync API capabilities, such as search filters, fields, and time-based checkpoints.
With data flowing into Splunk, you can create Splunk inputs with filters that sync only the assets with a certain protocol, discovery date, or open service.