Capabilities
Dataflect is a Splunk® application that allows you to query any API and interact with the data using Splunk's® native searching, reporting, alerting, and visualization. It enables you to enrich your Splunk® logs by correlating with data returned from any API and develop no-code Splunk® custom alert actions.

No-code Integration
Dataflect seamlessly integrates with various APIs, empowering you to access and utilize data from different sources within your Splunk's® environment.
​
Available as Dataflect Search, which includes a free version and enables the "Search" capability.
​
Also available as Dataflect, which includes all capabilities.

Search Data Anywhere
Query any API and return the results within a standard Splunk® search.
No-code custom search commands that provide granular role based access control.
Normalize API responses to the Splunk® Common Information Model using Splunk props.
Correlate, visualize, and alert on data returned from anything with an API.
​
Examples:
Search Azure Blob Storage
Search threat intelligence feed, create lookup
Search assets/identities stored in IdP​

Enrich Your Logs
No-code custom scripted lookups.
Enrich your logs with information from any API.
Examples:
Geolocation
WHOIS lookup
Check against known IOCs
Check for mentions on social media

Engage With Any API
No-code custom alert actions.
Engage with any API based on events discovered in Splunk®.
Examples:
Disable a user account
Add a firewall block
Which One is Right For Me?
Offering | Capabilities | Limitations | Recommended For |
---|---|---|---|
Dataflect |
| Unlimited |
|
Dataflect Search Unlimited |
| Unlimited searches |
|
Dataflect Search Premium |
| 500 Searches per month |
|
Dataflect Search Free |
| 150 Searches per month |
|
Offering | Limitations |
---|---|
Dataflect | Unlimited |
Dataflect Search Unlimited | Unlimited searches |
Dataflect Search Premium | 500 Searches per month |
Dataflect Search Free | 150 Searches per month |