Distribution kit

Kaspersky Threat Feed App for Splunk Cloud is distributed as an archive named Kaspersky_Threat_Feed_App_for_Splunk_Cloud.tar.gz. The content of the archive is described in the following table.

Kaspersky Threat Feed App for Splunk Cloud package contents

Directory

Item

Description

default

 

macros.conf

List of macros for looking up indicators in CSV files.

commands.conf

List of scripts that run in the application.

collection.conf

List of variables stored in the application.

app.conf

Installer settings in Splunk Cloud.

savedsearches.conf

List of alerts in the application.

default/data/ui/views

 

Lookup_URL.xml

Dashboard for looking up indicators that contain a URL.

Lookup_IP.xml

Dashboard for looking up indicators that contain an IP.

Lookup_HASH.xml

Dashboard for looking up indicators that contain a HASH.

Info.xml

Dashboard for the Info tab of the application.

Settings.xml

Dashboard for the Settings tab of the application.

default/data/ui/nav

default.xml

Description of navigation in the application.

bin

 

kl_feed_for_splunk.py

Script for downloading feeds.

kl_feed_for_splunk.conf

Script configuration file.

ijson

Folder containing libraries for application operation.

splunklib

Folder containing libraries for application operation.

appserver/static

 

settings.js

Script for the Settings tab operation of the application.

kl_dashboard.css

Styles for the dashboards of the application.

info.js

Script for the Info tab operation of the application.

lookups

 

Folder containing lookup files.

metadata

default.meta

File containing permissions settings for the application.

static

appIcon_2x.png

appIcon.png

appIconAlt_2x.png

appIconAlt.png

appLogo_2x.png

appLogo_2x.png

Files with the application logos.

root directory

README.txt

Application description.

root directory

license.txt

End User License Agreement (License Agreement, or EULA).

root directory

legal_notices.txt

Terms of use of third-party code.

The distribution archive also contains other service files.

Page top