The Technical Add-on for Malwarebytes app is a prerequisite for all Malwarebytes apps for Splunk. The app includes Common Information Model (CIM) compliant field extractions and predefined source types for multiple Malwarebytes products making it compatible with all CIM based Splunk apps including Splunk Enterprise Security.
Requirements
To install the Technical Add-on for Malwarebytes app, you need:
- An active Splunk Enterprise or Splunk Cloud instance.
- User login credentials to Splunk.
Download Technical Add-on from Splunkbase
- Go to the Technical Add-on for Malwarebytes page in Splunkbase.
- Click on LOGIN TO DOWNLOAD.
- Enter your Splunk user credentials.
Install Technical Add-on for Malwarebytes
Where you install Technical Add-on for Malwarebytes is based on your Splunk environment.
Splunk Enterprise Single Instance Environments
Install the Technical Add-on for Malwarebytes in the same location where the Splunk components, Search Tier, Indexer Tier, and Forwarder Tier are located. For instructions on installing add-on in a single instance environments, refer to Splunk's support article Install an add-on in a single-instance Splunk Enterprise deployment.
Splunk Enterprise Distributed Environments
Install the Malwarebytes Cloud Remediation app where your Search Tier, Indexer Tier, and Forwarder Tier are located. For instructions on installing an add-on in a distributed Splunk Enterprise environment, refer to Splunk's support article Install an add-on in a distributed Splunk Enterprise deployment.
Once the Technical Add-on for Malwarebytes is installed, you can now install the Malwarebytes Visibility and Dashboards app, Agentless Remediation app, or Cloud Remediation app for your Splunk environment.
Configure Technical Add-on for Malwarebytes
- In Splunk>enterprise, click on the Apps cog icon.
- On the Apps page, locate Technical Add-on for Malwarebytes then click Set up.
- Complete the following fields:
- In the Enter Company Name field, enter your company's name.
- In the Enter Company Email field, enter your company's email address.
- In the Malwarebytes Cloud AccountID/MBBR License Key field, enter the license key for your Malwarebytes Nebula subscription.
- Click Save to complete the setup process.