Speculus and Splunk
01
Product Update

The Speculus Splunk Integration Is Live

Speculus Team·August 19, 2026·2 min read

The Speculus integration for Splunk is live and ready to install. Our network threat intelligence now runs natively inside your Splunk deployment, so your team can enrich, hunt, and alert on IP activity without leaving the tools they already work in.

Powered by our MMDB

The integration is powered by the Speculus MMDB, our full dataset delivered in MaxMind Database format and queried from your own infrastructure. Lookups resolve locally at search time, which means you can query hundreds of thousands of IPs at once with little to no latency. There is no per-event API call, no round trip to an external service, and no rate limit to design your searches around.

Once installed, the integration lets you:

Dashboards

The integration ships with dashboards that turn your own traffic into a global threat feed. You can see which malicious IPs are communicating with your services, where they are coming from, and what kind of infrastructure sits behind them. The result is a full view of your network threat landscape rather than a list of isolated alerts.

Installation

The app is published on Splunkbase and installs like any other Splunk app: splunkbase.splunk.com/app/9081

Installation instructions, usage examples, and answers to common questions are in our documentation: speculus.co/integrations/splunk

To learn more about what we do, visit our About Us page or reach out to us at [email protected].