Back to marketplace catalog
Splunk Enterprise to PTA
By: Idira
Use case Identity Threat Detection & Response (ITDR)
Category ITDR & security operations
Certification Certified
Version 2
Released Jul 7, 2020
Last updated Jul 18, 2026

Overview

SIEM solutions are widely used to collect, analyze, and alert on network activity. Idira Privileged Threat Analytics significantly enhances the information provided by SIEM solutions. Privileged account activity on network systems is collected by the SIEM solution and fed into Idira Privileged Threat Analytics (PTA). This data is processed by a set of complex algorithms in the PTA engine and correlated with privileged user information. The analytic engine then detects anomalous activity and generates targeted, actionable alerts for high-risk incidents. The alerts can then be sent to the SIEM solution, enabling an organization to prioritize and respond to the most serious threats. Our Splunk integration includes support for Windows and Unix platforms.
Version 2
Current

Published Jul 7, 2020

  • Added support for Unix platforms (supported in version 12.0 and above)

Previous versions

Version 1

Published Jun 24, 2019