<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can splunk Enterpise import Threat intelligence in STIX and XML format (Not splunk Enterprise Security) in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337522#M6593</link>
    <description>&lt;P&gt;Why not try Splunk SA- Splice ? Does a great job &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2637/"&gt;https://splunkbase.splunk.com/app/2637/&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Aug 2017 16:02:54 GMT</pubDate>
    <dc:creator>klaxdal</dc:creator>
    <dc:date>2017-08-01T16:02:54Z</dc:date>
    <item>
      <title>Can splunk Enterpise import Threat intelligence in STIX and XML format (Not splunk Enterprise Security)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337520#M6591</link>
      <description>&lt;P&gt;As the subject, can splunk enterprise import Threat Intelligence in STIX and XML format with less features in Splunk Enterprise as I only have splunk Enterprise but no Splunk ES? (But the Splunk ES had many features seem to be not very useful and we only want to try the threat intelligence part.&lt;/P&gt;

&lt;P&gt;Splunk ES can do it by below method, any similar thing in Splunk Enterprise?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Addthreatintel"&gt;http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Addthreatintel&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Uploadthreatfile"&gt;http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Uploadthreatfile&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Jul 2017 06:43:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337520#M6591</guid>
      <dc:creator>netinstall</dc:creator>
      <dc:date>2017-07-29T06:43:42Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk Enterpise import Threat intelligence in STIX and XML format (Not splunk Enterprise Security)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337521#M6592</link>
      <description>&lt;P&gt;hello there,&lt;BR /&gt;
i don t see why cant you do it in Splunk Core.&lt;BR /&gt;
you can create a modular input or a scripted input to look for these files and either index them or upload as a lookup so you can run searches and correlation against them.&lt;BR /&gt;
with not much effort, i was able to use that link: &lt;A href="http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Downloadthreatfeed#Add_a_URL-based_threat_source" target="_blank"&gt;http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Downloadthreatfeed#Add_a_URL-based_threat_source&lt;/A&gt;&lt;BR /&gt;
downloaded the "ransomware_domain_blocklist" from here:&lt;BR /&gt;
&lt;A href="https://ransomwaretracker.abuse.ch/downloads/RW_DOMBL.txt" target="_blank"&gt;https://ransomwaretracker.abuse.ch/downloads/RW_DOMBL.txt&lt;/A&gt;&lt;BR /&gt;
and uploaded as a lookup table to my splunk, see screenshot:&lt;BR /&gt;
&lt;IMG src="https://community.splunk.com/storage/temp/206986-ransom.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;you can use this method for STIX and all other online lists.&lt;BR /&gt;
the challenge is to keep them updated. and thats where a scripted input or modular input comes in handy.&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:09:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337521#M6592</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2020-09-29T15:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can splunk Enterpise import Threat intelligence in STIX and XML format (Not splunk Enterprise Security)</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337522#M6593</link>
      <description>&lt;P&gt;Why not try Splunk SA- Splice ? Does a great job &lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/2637/"&gt;https://splunkbase.splunk.com/app/2637/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Aug 2017 16:02:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Can-splunk-Enterpise-import-Threat-intelligence-in-STIX-and-XML/m-p/337522#M6593</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2017-08-01T16:02:54Z</dc:date>
    </item>
  </channel>
</rss>

