Notable events by technique
Map Splunk notables to MITRE ATT&CK and see coverage gaps per tactic.
Splunk events and notable alerts streamed into Kimo and correlated with OSINT, assets and threat intelligence.
Live demo workspace with fictional data · no signup, no credentials needed

Splunk on its own answers half the question. Joined with the rest of your stack in Kimo, it answers the other half.
Map Splunk notables to MITRE ATT&CK and see coverage gaps per tactic.
Match indicators from Splunk events against open-source and partner feeds in real time.
Alert volume, false-positive rate and time-to-triage per rule and per shift.
Kimo maps Splunk into clean, typed tables with primary keys and incremental cursors, so syncs stay fast and joins just work.
| Field | Type | Notes |
|---|---|---|
| event_id | id | Primary key |
| _time | string | |
| rule_name | string | |
| urgency | string | |
| src | string | |
| dest | string |
This model ships with the Defense Intelligence demo. Open it to see every join and measure.
OSINT signals and SIEM events correlated by entity, zone and time window.

Fictional data · hover the chart for daily values
No engineers, no pipelines to maintain. Kimo asks for the minimum access it needs and tells you exactly what it will read.
Issue a token or account scoped to the indexes, topics or feeds Kimo should read.
Allow Kimo’s static egress IPs, use an SSH tunnel, or run the on-prem agent inside your network.
Credentials are encrypted at rest with a per-workspace key and tested before saving.
Choose what to sync, starting with notable_events. Kimo backfills, then keeps it fresh.
Read-only, encrypted, revocable. Credentials are encrypted with a per-workspace key, never logged, and can be rotated without breaking your models.
Splunk is ingested as a stream. New records typically appear in models and maps within a few seconds.
Try it on the live demo workspace first, then connect your own account when you are ready.