<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to send data from Splunk to &amp;quot;TheHive&amp;quot;(ticketing tool)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292222#M55681</link>
    <description>&lt;P&gt;Thanks for some valuable information. &lt;/P&gt;

&lt;P&gt;To integrate I mean to send data from Splunk to hive and auto incident to be created  when any alert triggers. &lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2017 06:28:31 GMT</pubDate>
    <dc:creator>bagarwal</dc:creator>
    <dc:date>2017-07-05T06:28:31Z</dc:date>
    <item>
      <title>How to send data from Splunk to "TheHive"(ticketing tool)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292220#M55679</link>
      <description>&lt;P&gt;Hello Everyone, &lt;/P&gt;

&lt;P&gt;I am working to integrate "TheHive" i.e. ticketing tool like Demisto with Splunk.  I searched in SplunkBase but there is no app available for TheHive. &lt;/P&gt;

&lt;P&gt;Can anyone please guide me how I can start with integration or steps need to follow. &lt;/P&gt;

&lt;P&gt;Many thanks in advance. &lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Binay Agarwal &lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 06:15:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292220#M55679</guid>
      <dc:creator>bagarwal</dc:creator>
      <dc:date>2017-06-30T06:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data from Splunk to "TheHive"(ticketing tool)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292221#M55680</link>
      <description>&lt;P&gt;I don't use TheHive (and never heard of it before), but some ideas...&lt;/P&gt;

&lt;P&gt;First, when you say integrate, do you mean send alerts to hive from splunk?  Or bring data from hive into splunk for analysis?  Or both?&lt;/P&gt;

&lt;P&gt;If alerting, it depends on what hive offeres.  For example, if there is an API then maybe you can use a &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Webhooks"&gt;webhook&lt;/A&gt;.  Or if not, but there is someway to automate it, then you could &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Alert/Runscriptaction"&gt;run a script&lt;/A&gt; when an alert fires (or an eqivalent custom action).  I did find &lt;A href="https://github.com/CERT-BDF/TheHive4py"&gt;this&lt;/A&gt; referenced on their site which seems like it might be a good option.&lt;/P&gt;

&lt;P&gt;For analysis, same question but the other way.  Do they allow you to get data out of it?  Maybe via an API?  or is the data stored in database that you can get access to (in which case use dbconnect).  Etc.  At that point, just use splunk normally to get at the data.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 15:46:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292221#M55680</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2017-06-30T15:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data from Splunk to "TheHive"(ticketing tool)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292222#M55681</link>
      <description>&lt;P&gt;Thanks for some valuable information. &lt;/P&gt;

&lt;P&gt;To integrate I mean to send data from Splunk to hive and auto incident to be created  when any alert triggers. &lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2017 06:28:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292222#M55681</guid>
      <dc:creator>bagarwal</dc:creator>
      <dc:date>2017-07-05T06:28:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data from Splunk to "TheHive"(ticketing tool)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292223#M55682</link>
      <description>&lt;P&gt;To create alerts in the hive based on Splunk searches you may have a look st &lt;A href="https://github.com/remg427/misp42splunk"&gt;https://github.com/remg427/misp42splunk&lt;/A&gt;&lt;BR /&gt;
Although meant to pull and push attributes in MISP you can easily connect to TH&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jan 2018 22:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/292223#M55682</guid>
      <dc:creator>remiseguy</dc:creator>
      <dc:date>2018-01-30T22:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to send data from Splunk to "TheHive"(ticketing tool)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/599790#M104581</link>
      <description>&lt;P&gt;Any brand new improvements on the entagration of splunk and the hive ??&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 05:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-send-data-from-Splunk-to-quot-TheHive-quot-ticketing-tool/m-p/599790#M104581</guid>
      <dc:creator>Jaseemin</dc:creator>
      <dc:date>2022-05-31T05:12:43Z</dc:date>
    </item>
  </channel>
</rss>

