Cyences Documentation
Splunkbase Download Add-on: https://splunkbase.splunk.com/app/5659
Splunkbase Download App: https://splunkbase.splunk.com/app/5351/
Overview
The Cyences App for Splunk gives security teams complete, out-of-the-box visibility into their environment’s security posture. It was built to be a seamless part of the Blue Team arsenal for security engineers, SOC analysts, and administrators — delivering value on day one without the heavy configuration and fine-tuning that traditional security frameworks demand.
Cyences ships with 300+ pre-built detection rules, per-technology dashboards, automated device and user inventory, and a forensic investigation interface built around the MITRE ATT&CK framework to quickly pinpoint areas of concern. Security use cases are organized into SOC and Compliance categories so each team reviews only what is relevant to them. Alerts are disabled by default and enabled per environment, so teams get signal without noise — and Cyences receives continuous enhancements that expand coverage and deepen automation, AI, and correlation capabilities.
@CrossRealms International, we use Cyences as a core part of our Unified Cyber Management Center (UCMC). For more detail, refer to the UCMC Blog.
By default, the Cyences app provides alerts and dashboards across the following categories:
- Antivirus / Antimalware
- CrowdStrike
- Kaspersky
- Office 365 Defender ATP
- Sophos Endpoint Protection
- Trendmicro
- Windows Defender
- Microsoft Defender for Cloud
- Cloud Tenancies
- Amazon Web Services
- Google Workspace
- Microsoft Office 365
- Microsoft Azure Active Directory
- Azure Cloud Services
- Azure PIM (Privileged Identity Management)
- Microsoft Azure Graph Security Score
- Email
- Microsoft Office 365
- Google Workspace (Gmail)
- Mimecast
- Database
- MSSQL
- Oracle
- PostgreSQL
- Network Devices
- Cisco IOS
- Fortinet FortiGate
- Palo Alto Networks
- Sophos Firewall
- Cisco Meraki
- F5 BIGIP
- Cloudflare
- Appgate SDP
- Imperva WAF
- Imperva DAM
-
Web Application
- Vulnerability Scanners
- CrowdStrike Spotlight
- Qualys
- Tenable
- Nessus:Pro (Nessus Professional)
- Tanium
-
Active Directory / Azure Active Directory
- Windows
- Windows Patch
- Sysmon
- Ransomware
-
Linux / Unix
-
Authentication
- VPN
- Cisco Anyconnect
- Fortinet FortiGate
- GlobalProtect (Palo Alto)
- Sophos
- pfSense OpenVPN
-
DNS
-
Lansweeper
-
DUO
-
Forcepoint DLP
-
Delinea PAM
- RSA Radius Authentication
- From Palo Alto system logs
Apart from alerts and dashboards, the Cyences App also integrates with other well-known tools to create intelligence dashboards that strengthen your security investigation and auditing processes:
- Intelligence
- Device Inventory Table
- User Inventory Table
Cyences also offers a number of unique, first-in-the-market capabilities on Splunk — Alert Digest, Device Inventory, User Inventory, Network Telemetry, SOAR Integration, SOC AI Integration, and more:
-
Alert Digest and Critical Email Alert: Cyences provides a smarter way to consume Splunk alerts so users are not spammed by a flood of individual emails. Configure your email address once and receive every critical event from all alerts immediately, while keeping your inbox clean. The Alert Digest sends all medium- and high-severity notable events from every alert as a single daily summary email. SOC and Compliance alerts can be configured independently. Please refer to the Cyences Alerts Configuration section for the configuration guide and more information.
-
Device Inventory and Intelligence: The Device Inventory Table is a vital security-audit tool that requires zero configuration. It lists all devices in an environment by correlating data from CrowdStrike, Lansweeper, Kaspersky, Qualys, Sophos, Tenable, Nessus:Pro, Tanium, Windows Defender, and more. The companion “Intelligence” dashboard provides a full per-device picture — vulnerability summary, antivirus status, VPN/auth activity, and related Splunk alerts — making it invaluable for investigating a security incident. For more information, please refer to the Device Inventory and Intelligence section.
-
User Inventory: The User Inventory Table provides information about users in an environment and user-related metadata — the number of users by type, the products each user is associated with, privilege flags used to escalate alert severity, and more. For more information, please refer to the User Inventory section.
-
Network Telemetry: The “Network Telemetry” dashboard surfaces critical information for security teams. It shows whether there is active traffic on a port of a machine that is vulnerable (or has a known vulnerability) — revealing whether a vulnerability in your environment is actively being exploited, not just theoretically exposed.
-
SOAR Integration: Cyences can automatically forward notable events to your SOAR platform (e.g., Splunk SOAR / Phantom) via a built-in SOAR alert action, sending each event as a CEF-formatted artifact. A dedicated SOAR configuration page lets you set the SOAR URL, authentication token, event label, and sensitivity — and enable or disable the integration — without editing configuration files, and failed events are retried automatically so no alert is silently dropped. Please refer to the SOAR Integration section for the configuration guide and more information.
-
SOC AI Integration: Splunk events are often hard to interpret without deep event-logging and domain knowledge. This feature provides a meaningful, human-readable interpretation of complicated Splunk events directly within Cyences. Please refer to the SOC AI Integration section for the configuration guide and more information.
-
Easy Setup with the Products Setup UI: Cyences includes a React-based configuration page that makes setup fast and simple — enable or disable products per environment, verify data-source macros (index/sourcetype), review live data-coverage and data-model acceleration status, check dependent add-on installation, and choose which dashboards and Overview panels are visible, all without editing configuration files by hand.
-
Custom Alert Builder: SOC teams can create custom alert rules through a built-in UI without writing SPL directly. Custom alerts get full feature parity with native Cyences alerts — they appear on the Overview page, trigger critical and digest email notifications, and show up in the Forensics and Intelligence dashboards.
The Cyences App is a contribution-based project that anyone can provide suggestions for. Refer to the following link to offer general feedback or to report an issue: https://github.com/CrossRealms/Splunk-Cyences-App-for-Splunk/issues
Visit the Cyences repository on GitHub for more information: https://github.com/CrossRealms/Splunk-Cyences-App-for-Splunk