Blog

Announcement: Non-Employee Risk Management Splunk Add-on now available via CoLab

Author

  • jeff_lakey

    SailPoint

Background

To maintain a strong security posture, Non-Employee Risk Management customers had a need to integrate the application with the SIEM (Security Information and Event Management). For this reason, we released the Audit History APIs last year. By creating and exposing new API endpoints for Profile, Workflow, and Configuration history, we provided the ability for customers to write integrations with their existing SIEM or Business Intelligence tools, and ensure their non-employee data is easily reflected in their existing security and audit practices.

What's new?

The SailPoint Non-Employee Risk Management Splunk Add-on is a community-developed, open-source integration built using the Splunk Add-on Builder. It allows organizations to collect, parse and normalize audit data from SailPoints Non-Employee Risk Management API directly into Splunk.

Designed for security teams, this add-on provides visibility into non-employee identity governance by seamlessly ingesting SailPoint logs into Splunk’s search and analytics engine.

It leverages Splunk’s onboarding framework to support both Splunk Enterprise and Splunk Cloud deployments, helping teams monitor access activity, audit eventsand compliance risks accross the non-employee identity lifecycle.

Where can I find it?

The Non-Employee Risk Management Splunk Add-on is available in the SailPoint Developer Community CoLab.

For more information, including the Legal Agreement, add-on Guide, a link to the add-on, requirements, and a link to the add-on itself, please visit this link:

https://developer.sailpoint.com/discuss/t/non-employee-risk-management-splunk-add-on/106887