VirusTotal token configuration

This document explains step-by-step how to configure the API token required for the VirusTotal App to work properly in Splunk. The token is provided by VirusTotal and is needed to perform API lookups and enrich data directly from Splunk.

1. Prerequisites

Before you start, make sure you have:

✔ A VirusTotal account

You can create it on the official VirusTotal website.

✔ An API token (VirusTotal API Key)

You will find it in your user profile:

VirusTotal → User Profile → API Key

✔ Splunk Enterprise / Splunk Cloud access

With permissions to install apps and access their configuration pages.

2. Accessing to the Set up page of VirusTotal App

  1. Log in to your Splunk instance.
  2. Navigate to the set up page: Apps → Manage Apps → VirusTotal App and click on «Set up» option

3. Configuring the VirusTotal Token

The VirusTotal App includes a dedicated menu for configuring the API token.

  1. Go to the API Key tab:
  2. Paste your VirusTotal API token here.
  3. Click Save API Key.
  4. Once saved, the app is ready to perform VirusTotal lookups.