Introducing a New Splunk Add-On for OT Security
We’ve worked with customers on these challenges for many years, and are excited to share some additional capabilities available as of today to help organizations improve the security posture of their OT environments. We are introducing a new Splunk add-on for OT Security, to enable organizations that operate assets, networks and facilities across both carpeted (IT) and concrete (OT) environments to better apply Splunk® Enterprise Security to improve threat detection, incident investigation and response. This add-on expands the capabilities of Splunk’s data platform to monitor for threats and attacks, compliance, incident investigation, forensics and incident response across a broad spectrum of assets and topologies — from email servers to PLCs — that define modern manufacturing, energy and public sector organizations.
What is the Splunk Add-On for OT Security?
- Expanded ability to ingest and monitor OT Assets
- Improved OT and Application Vulnerability Management including defined applications of MITRE ICS Attack
- Interfaces and reports to support customer compliance and audit with NERC CIP
These capabilities are delivered in the new add-on now available on Splunkbase, including detailed documentation that outlines installation, related Technology Add-ons, a reference architecture and a number of knowledge objects that support enhanced OT security monitoring. Included objects span new and modified searches, dashboards and panels, reports, KSIs, lookups and extensions to Splunk Enterprise Security frameworks.
The Splunk add-on for OT Security is built to enable improved integration with leading OT security technologies including inventory discovery and management systems, network monitoring and anomaly detection solutions, endpoint monitoring and patch management tools. We have worked closely with many leading OT security vendors, including Armis, Forescout, Langner, Nozomi and others to enable high value data access and visibility.
To find out more about this add-on for OT Security, you can download our whitepaper, "Protecting Operational Technology With Splunk." You can also download the app yourself from Splunkbase, reach out to your Splunk account team or our OT security experts directly at OTsecurity@splunk.com.
----------------------------------------------------
Thanks!
Ed Albanese
Related Articles

Delivering the Ultimate SOC Analyst Experience: Ending Fatigue with Splunk Enterprise Security

Splunk Security Content for Threat Detection & Response: December Recap
