Proxy configuration

The VirusTotal App for Splunk allows you to configure a proxy connection in case your Splunk environment requires outbound traffic to be routed through a proxy server. This configuration is available from the app’s Set up page.

1. Accessing to the Set up page of VirusTotal App

  1. Log in to your Splunk instance.
  2. Navigate to the set up page: Apps → Manage Apps → VirusTotal App and click on «Set up» option

2. Configuring the proxy

The VirusTotal App includes a dedicated menu for configuring the Proxy token.

  1. Go to the Proxy tab:
  2. Inside the configuration switch to Use Proxy. When Use Proxy is enabled, the following fields become available:
    • Proxy Protocol: Dropdown that allows selecting the protocol used by the proxy server, http or https
    • Proxy Host: The hostname or IP address of the proxy server. Example: proxy.company.local
    • Proxy Port: The port number used by the proxy server. Example: 8080
  3. Enabling Proxy Authentication (Optional)
    If your proxy server requires authentication, the configuration page includes another switch to enable Proxy Authentication. When is enabled, the following fields needs to be filled:

    • Proxy Username: The username required to authenticate to the proxy server. Example: service.splunk
    • Proxy Password: The password associated with the proxy username. This field is stored securely using Splunk’s internal credential storage.
  4. Saving Proxy Configuration.
    Once all required fields are completed, click Save Proxy Settings. The VirusTotal App will store the proxy settings and use them for all outgoing API requests.