Skip to main content

20. August 2026

Workspace ONE Mobile Threat Defense Splunk Integration Guide

You can integrate Workspace ONE Mobile Threat Defense with your on-prem or cloud Splunk environment using the Lookout Mobile Threat Defense for Splunk app version 2.0 to stream Workspace ONE Mobile Threat Defense threat, device, and audit events into your Splunk environment.

Supported Lookout Splunk Apps

This table describes the Splunk versions supported by Lookout Mobile Threat Defense for Splunk app. With version 8.0, Splunk deprecated Python 2.x requiring all plugin applications to support Python 3.x. All versions of the Lookout Mobile Threat Defense for Splunk application support Python 3.x.

The Development Splunk Version column documents the specific version of Splunk used to develop the Lookout Mobile Threat Defense plugin. The Supported Splunk Versions column documents what major versions of Splunk that the plugin works with.

Lookout Mobile Threat Defense for Splunk VersionDevelopment Splunk VersionSupported Splunk Versions
1.5.xn/aSplunk Enterprise, Splunk Cloud 9.1, 9.0, 8.2, 8.1, 8.0
2.0.xSplunk Enterprise 9.0.4.1 (build 419ad9369127)

running on: Amazon Linux 2023 - 6.1.19-30

Splunk Cloud 9.0.2209.4
Splunk Enterprise, Splunk Cloud 9.1, 9.0, 8.2, 8.1, 8.0

Requirements, Splunk

  • An active Splunk Enterprise license and Splunk administrator credentials.
  • Full Administrator access to the Workspace ONE Mobile Threat Defense Console.

Install or Upgrade the Lookout App, Splunk

Use this procedure to install the Lookout Mobile Threat Defense for Splunk app directly from the app store to a Splunk environment. Use this same procedure to upgrade from a previous app version.

  1. Log in to the Splunk web console.
  2. Go to the Manage App page and select Browse More Apps.
  3. Enter Lookout into the search box in the upper left-hand corner and press Enter.
  4. When the Lookout application card appears, select Install to start the installation. A log in and install prompt appears.
  5. Enter your username and password, and select Agree and Install to continue.
  6. Click Done.

Migrate from v1.5 to v2, Splunk

  1. Run the old and the new Splunk versions in parallel.
  2. Search for events from the old version using source= lookout.
  3. Search for events from the new version using source= lookout_v2.
  4. Stop using the old version when the new version is functional.

Uninstalling the Lookout App, Splunk

  1. Go to the Lookout app and select Reset to clear all the connections.
  2. Make Home the current app (select on Splunk > Cloud).
  3. Click the Manage Apps tab
  4. Click Uninstall. To uninstall the Lookout App from Splunk On Prem:
  5. Go to the Lookout app and select Reset to clear all the connections.
  6. Remove the app directory from $SPLUNK_HOME/etc/apps
  7. Restart Splunk.

Set up the Lookout App, Splunk

  1. Obtain an application key from your Workspace ONE Mobile Threat Defense tenant. The key authenticates your Lookout app to the Mobile Risk API.
  2. Paste the application key when entering other parameters in the app configuration procedure.

Obtain an Application Key, Splunk

The App authenticates with the Lookout Mobile Risk API using OAuth 2.0. You need to have an application key specific to your Workspace ONE Mobile Threat Defense tenant to properly configure your Lookout app. To retrieve your application key:

  1. Log into the Workspace ONE Mobile Threat Defense Console as an administrator.
  2. Select System > Application Keys.
  3. Click Generate an application key and enter a descriptive label name.
  4. Capture your generated key by selecting Click to Copy Application Key to Clipboard. This copies the key to your clipboard. This key is unique for the data in your Workspace ONE Mobile Threat Defense tenant.
  5. Immediately copy the generated key into a text file for safe keeping as you will not be able to see the key again after this procedure.

Configure the App, Splunk

  1. From the Splunk web console homepage, navigate to the Lookout application by selecting Lookout Mobile Threat Defense for Splunk from the left-hand navigation panel.

  2. Splunk notifies that the app is not configured. Click Continue to app setup page.

  3. Complete setup by entering the following information.

    Field NameValue or Description
    Mobile Risk API Endpointhttps://api.lookout.com
    Proxy Endpoint (Optional)Address of a HTTP or HTTPS proxy server if Splunk is configured behind a proxy server.
    Proxy UsernameProxy server administrator username
    Proxy PasswordProxy server administrator password
    Enterprise nameCompany name used to tag events.
    API KeyAPI Key to access Lookout services generated from Workspace ONE Mobile Threat Defense Console.

    IMPORTANT: After pasting the key into the App configuration field, delete the text file to prevent it from being stolen.

    The plugin will not display the API key again after you submit the configuration.
    Starting Stream PositionLookout Mobile Risk API stream position to start event retrieval. The default is now which retrieves events starting from when you submit this configuration. To set a different stream position, enter a positive integer.
    Add Connection (Optional)Select the Add Connection button to add additional API keys to pull Lookout events from multiple enterprises.
  4. Click Submit at the bottom of the page.

Once submitted, the plugin begins forwarding MRA events to Splunk in batches of 100 events every 30 seconds. (Splunk Enterprise customers can change the 30 second interval, see Configure the Data Input Script (Splunk Enterprise Only) for details.

Manage your Mobile Risk API Connections, Splunk

Use the Manage Connections tab to view and update your existing configuration. For security, the Lookout API Key and Splunk credentials are hidden from view. You can:

  • Edit connection parameter values
  • Add a Mobile Risk API connection

Edit Parameter Values, Splunk

  • Proxy Endpoint, Username, Password

  • For each connection:

    • Enterprise Name
    • Lookout API Key
    • Event Type
    • Active/Inactive toggle

    To edit a parameter:

    1. Overwrite one or more parameter values with updated values.
    2. Click Submit.

Add a Mobile Risk API Connection, Splunk

  1. Click Add Connection.
  2. Enter required configuration values.
  3. Click Submit.

Configure the Data Input Script (Splunk Enterprise Only)

Add Lookout Mobile Threat events to Splunk cloud using a data input script. To configure the data input script:

  1. Click Settings > Data Inputs from the top right corner.

  2. In the Data Inputs window, select the Scripts button to view a list of all data input scripts currently installed.

  3. Click the link associated with the custom lookout script to open the edit screen:

    $SPLUNK_HOME/etc/apps/lookout_mobile_threat_defense_for_splunk/bin/mra_event_runner_splunk.py

  4. Enter the following information.

    Field NameField Description
    IntervalNumber of seconds to wait before rerunning the script. 60 seconds is the default. Enter as an integer or in chronological format.
    Source name overridelookout (All Lookout Mobile Threat events are tagged with lookout_v2 as their source.)
    Set SourcetypeChoose Manual from the dropdown.
    Source typejson_no_timestamp

Splunk Fields

For details showing mappings of Lookout event fields to key-value fields see the Mobile Risk API Guide.

Pausing and Resuming a Connection, Splunk

To stop receiving events from a Connection, you can pause it. When you are ready to receive the events, you can resume the Connection.

  1. In the Splunk web console, navigate to the Lookout app Lookout Mobile Threat Defense for Splunk.
  2. For the Connection that you want to pause, toggle the Connection Active switch to disabled. The app pauses and saves the current stream position.
  3. Resume sending events by toggling the Connection Active switch to enabled. The app resumes from the saved stream position.

Handling Errors, Splunk

When the application is functioning normally, the UI updates the Event Count, Last Fetched, and Current Stream Position fields. Use the Refresh button in the bottom right of the plugin to loan the most recent data, the UI does not automatically refresh.

FieldBehavior
Last FetchedIncrements by the configured interval. The timestamp displayed for the last fetch uses the local time zone setting of Splunk.
Event CountIncrements when the Mobile Risk API generates events.
Current Stream PositionIncrements when the Mobile Risk API generates events.

All Splunk customers can access Splunk s splunkd.log file. See the Splunk documentation for how to access the log file on both enterprise and cloud.

Hint: On Splunk Cloud, copy the following into the search bar in the Search & Reporting application:

index=_internal sourcetype=splunkd
source="/opt/splunk/var/log/splunk/splunkd.log"

Only Splunk Enterprise customers can download the application s app.log file directly from the Splunk server. This is because of technical restrictions on the application s powers within a Splunk Cloud instance versus Splunk Enterprise.

To download the application s app.log file (Enterprise customers), select Download Logs on the Manage Connections page when not in edit mode.

To support Splunk Cloud customers, some debugging information displays in the case of an error retrieving events. Any exception that the python script throws during event retrieval for a connection is logged to the lookout_mra_history record and then appears as an error message. This might not capture exactly what is happening with the application, in which case, search the splunkd.log file for Lookout related messages. Additionally, the full application log is searchable using the Search & Reporting app. This is true for both Splunk Enterprise and Splunk Cloud.

Enter this line into the Search & Reporting application:

index=_internal source="/opt/splunk/var/log/splunk/lookout_mobile_threat_defense_for_splunk.log"

Lookout directs almost all logging to the lookout_mobile_threat_defense_for_splunk.log file located at <SPLUNK_HOME>/var/log/splunk/. The file has been relocated to Splunk's logging directory as it allows the log to be searchable using the Search & Reporting app.

The only time messages appear in the main log file splunkd.log is if there is an unhandled exception, which is rare.

Error Mappings, Splunk

Syslog FieldTypeDescription
typeEvent typeStatic value of ERROR
idStringUnique ID identifying the error event.
eventTimeDateTimeDate and time of the error event.
entNameStringEntity name for the error event.
msgStringDescription of the error.

The following is an example of a syslog format error event.

type=ERROR, id=437439f8-fb4a-43c0-95c5-4cc2a9688f27, eventTime=2017-03-22T12:45:07, entName=testEntName, msg=Error while polling events from Lookout Mobile Risk API

War diese Seite hilfreich?

Feedback zu diesem Thema geben

War dieses Thema hilfreich?

Bitte geben Sie keine personenbezogenen oder vertraulichen Daten an.

Link wird erstellt…