<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to integrate openCTI with Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/689716#M114787</link>
    <description>&lt;P&gt;Hi &lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268581" target="_blank"&gt;&lt;SPAN style="color:var(--ck-color-mention-text);"&gt;&lt;U&gt;&lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;@tuts&lt;/SPAN&gt; &lt;/U&gt;&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I’m a Community Moderator in the Splunk Community.&lt;/P&gt;
&lt;P&gt;This question was posted 1 year ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the &amp;nbsp;visibility it deserves. To increase your chances of getting help from the community, follow &lt;A href="http://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions" target="_blank"&gt;&lt;U&gt;these guidelines&lt;/U&gt;&lt;/A&gt; in the Splunk Answers User Manual when creating your post.&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2024 14:22:08 GMT</pubDate>
    <dc:creator>DanielPi</dc:creator>
    <dc:date>2024-06-05T14:22:08Z</dc:date>
    <item>
      <title>How to integrate openCTI with Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649623#M113637</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm currently working on a project where I aim to integrate the OpenCTI platform with Splunk in order to receive intelligence feeds,&amp;nbsp;how can i configure the ingestion of this intelligence feeds ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Any advice, tips, or resources you can provide will be highly appreciated&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2026 16:36:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649623#M113637</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2026-04-01T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649632#M113638</link>
      <description>&lt;P&gt;A bit of Googling and searching the OpenCTI web site turned up this connector:&amp;nbsp;&lt;A href="https://github.com/OpenCTI-Platform/connectors/tree/master/stream/splunk" target="_blank"&gt;https://github.com/OpenCTI-Platform/connectors/tree/master/stream/splunk&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 13:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649632#M113638</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-07T13:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649761#M113639</link>
      <description>&lt;P&gt;Thank you for your answers,&amp;nbsp;&lt;/P&gt;&lt;P&gt;So there is no configuration to do in splunk platform for this connection&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2023 21:40:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649761#M113639</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-07-09T21:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649762#M113640</link>
      <description>&lt;P&gt;I'm not saying that.&amp;nbsp; You may need to configure a sourcetype in props.conf for the data.&amp;nbsp; With luck, the connector documentation will let you know.&amp;nbsp; If the connector does not come with a Splunk props.conf file then you'll need to craft one yourself.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 00:05:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649762#M113640</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-10T00:05:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649942#M113641</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you for your response,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i checked the provided link, and i found that openCTI needs this information :&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="splk_user_0-1689066254722.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/26201iB1DCA5E90A28C21F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="splk_user_0-1689066254722.png" alt="splk_user_0-1689066254722.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So&amp;nbsp;what&amp;nbsp;&lt;SPAN&gt;value will the variable&amp;nbsp; "SPLUNK_TOKEN=Token1" and&amp;nbsp; "SPLUNK_OWNER=nobody " take ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And now do i still need to configure a sourcetype in props.conf for the data ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NB: i checked the props.conf file and i found just the syslog configuration&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 09:10:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649942#M113641</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-07-11T09:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649962#M113642</link>
      <description>&lt;P&gt;You will need to create a token for the connector to use.&amp;nbsp; Go to Settings-&amp;gt;Tokens for that.&lt;/P&gt;&lt;P&gt;I'm not sure what they expect for SPLUNK_OWNER.&amp;nbsp; Try it with "nobody" for now.&lt;/P&gt;&lt;P&gt;The screenshot doesn't say if props are needed or not.&amp;nbsp; The default syslog props may be sufficient, but you'll have to onboard some data to find out.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 11:21:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/649962#M113642</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-11T11:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650050#M113643</link>
      <description>&lt;P&gt;thank you ,&lt;/P&gt;&lt;P&gt;Well i tested the OpenCTI connector but the connection didn't work .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do i need to set up a kv store before or maybe i need to configure HTTP Event Collector&amp;nbsp;in order to integrate opencti to splunk.&lt;/P&gt;&lt;P&gt;i don't know also if this issues has a relation with REST API connection&lt;/P&gt;&lt;P&gt;The objective is to receive intelligence feeds from opencti platform in STIIX format to my splunk instance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NB: - I don't have the splunk entreprise app that provide the threat intelligence management section&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;- I'm using the free trial&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 19:24:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650050#M113643</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-07-11T19:24:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650069#M113644</link>
      <description>&lt;P&gt;The OpenCTI settings you showed earlier imply a KVStore is used and so must be created.&amp;nbsp; I see no mention of HEC, however.&lt;/P&gt;&lt;P&gt;I think the best place to direct your questions is to the OpenCTI team.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 00:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650069#M113644</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2023-07-12T00:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650123#M113645</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Jul 2023 08:51:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/650123#M113645</guid>
      <dc:creator>splk_user</dc:creator>
      <dc:date>2023-07-12T08:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/655941#M113646</link>
      <description>&lt;PRE&gt;&lt;SPAN class=""&gt;i am having a hard time integrating opencti into splunk, not sure if you have done it, can you help me&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Aug 2023 10:22:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/655941#M113646</guid>
      <dc:creator>splunk_newbie1</dc:creator>
      <dc:date>2023-08-29T10:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/680177#M113647</link>
      <description>&lt;P&gt;You are reading his request backwards.&amp;nbsp; That git project is for SENDING TO OpenCTI.&amp;nbsp; He (and I) need to RECEIVE FROM OpenCTI.&amp;nbsp; I cannot find anything that does this.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2024 17:40:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/680177#M113647</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2024-03-09T17:40:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/689712#M114785</link>
      <description>&lt;P&gt;Please I need the method if it is done with you&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:05:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/689712#M114785</guid>
      <dc:creator>tuts</dc:creator>
      <dc:date>2024-06-05T14:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate openCTI with Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/689716#M114787</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/268581" target="_blank"&gt;&lt;SPAN style="color:var(--ck-color-mention-text);"&gt;&lt;U&gt;&lt;SPAN style="background: var(--ck-color-mention-background); color: var(--ck-color-mention-text);"&gt;@tuts&lt;/SPAN&gt; &lt;/U&gt;&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;
&lt;P&gt;I’m a Community Moderator in the Splunk Community.&lt;/P&gt;
&lt;P&gt;This question was posted 1 year ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the &amp;nbsp;visibility it deserves. To increase your chances of getting help from the community, follow &lt;A href="http://docs.splunk.com/Documentation/Splunkbase/splunkbase/Answers/Questions" target="_blank"&gt;&lt;U&gt;these guidelines&lt;/U&gt;&lt;/A&gt; in the Splunk Answers User Manual when creating your post.&lt;/P&gt;
&lt;P&gt;Thank you!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2024 14:22:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-integrate-openCTI-with-Splunk/m-p/689716#M114787</guid>
      <dc:creator>DanielPi</dc:creator>
      <dc:date>2024-06-05T14:22:08Z</dc:date>
    </item>
  </channel>
</rss>

