<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VirusTotal API scan in workflow (http request) in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448022#M3983</link>
    <description>&lt;P&gt;"elpred0 · 7 hours ago    More...&lt;BR /&gt;
Hello,&lt;/P&gt;

&lt;P&gt;Configure the workflow action in post mode, URI: &lt;A href="https://www.virustotal.com/vtapi/v2/url/scan"&gt;https://www.virustotal.com/vtapi/v2/url/scan&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Post Arguments:&lt;BR /&gt;
apikey = your_apikey&lt;BR /&gt;
url = $field$&lt;/P&gt;

&lt;P&gt;It will open a json response with a perma link to your analysis."&lt;/P&gt;</description>
    <pubDate>Thu, 13 Sep 2018 18:46:35 GMT</pubDate>
    <dc:creator>vwolf80</dc:creator>
    <dc:date>2018-09-13T18:46:35Z</dc:date>
    <item>
      <title>VirusTotal API scan in workflow (http request)</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448019#M3980</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;

&lt;P&gt;I am working on a solution that requires a "workflow action" to give a drop down when searching against a "url" field when a search has been initiated for a User's URL/web history.&lt;/P&gt;

&lt;P&gt;We are filtering results from a security appliance for web traffic / firewall filtering.&lt;/P&gt;

&lt;P&gt;We use VirusTotal for the bulk of our URL scans for remediation.  I would like to click on the "Event Action (Verbose Mode)" and click on the custom VirusTotal workflow that I created.  We have a functioning WHOIS workflow function and it is working beautifully. But VirusTotal has certain restrictions on how data is fed to them via their website.&lt;/P&gt;

&lt;P&gt;I would love to have this function like the "WHOIS" search and pop the results via the VirusTotal website.&lt;/P&gt;

&lt;P&gt;I have researched all that I can so far, I do have a public API for searching if needed.&lt;/P&gt;

&lt;P&gt;Does anyone have any information on what to do next? I have listed below some examples for what VirusTotal provides.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.virustotal.com/vtapi/v2/file/scan/upload_url?apikey="&gt;https://www.virustotal.com/vtapi/v2/file/scan/upload_url?apikey=&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.virustotal.com/vtapi/v2/url/scan"&gt;https://www.virustotal.com/vtapi/v2/url/scan&lt;/A&gt;&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Thanks Everyone!&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 10 Sep 2018 20:44:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448019#M3980</guid>
      <dc:creator>vwolf80</dc:creator>
      <dc:date>2018-09-10T20:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal API scan in workflow (http request)</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448020#M3981</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Configure the workflow action in post mode, URI: &lt;A href="https://www.virustotal.com/vtapi/v2/url/scan"&gt;https://www.virustotal.com/vtapi/v2/url/scan&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Post Arguments:&lt;BR /&gt;
apikey = your_apikey&lt;BR /&gt;
url = $field$&lt;/P&gt;

&lt;P&gt;It will open a json response with a perma link to your analysis.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 11:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448020#M3981</guid>
      <dc:creator>osakachan</dc:creator>
      <dc:date>2018-09-13T11:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal API scan in workflow (http request)</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448021#M3982</link>
      <description>&lt;P&gt;This worked GREAT!!! Thanks for your help, however I would love to take the HTTPS response from Virustotal and run it in a separate browser window if possible.  &lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 18:00:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448021#M3982</guid>
      <dc:creator>vwolf80</dc:creator>
      <dc:date>2018-09-13T18:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal API scan in workflow (http request)</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448022#M3983</link>
      <description>&lt;P&gt;"elpred0 · 7 hours ago    More...&lt;BR /&gt;
Hello,&lt;/P&gt;

&lt;P&gt;Configure the workflow action in post mode, URI: &lt;A href="https://www.virustotal.com/vtapi/v2/url/scan"&gt;https://www.virustotal.com/vtapi/v2/url/scan&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Post Arguments:&lt;BR /&gt;
apikey = your_apikey&lt;BR /&gt;
url = $field$&lt;/P&gt;

&lt;P&gt;It will open a json response with a perma link to your analysis."&lt;/P&gt;</description>
      <pubDate>Thu, 13 Sep 2018 18:46:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448022#M3983</guid>
      <dc:creator>vwolf80</dc:creator>
      <dc:date>2018-09-13T18:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: VirusTotal API scan in workflow (http request)</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448023#M3984</link>
      <description>&lt;P&gt;Your welcome. Upvote/answer will be appreciated.&lt;/P&gt;

&lt;P&gt;Yep, that will be better but I think it would be far away from workflow action capacity.&lt;/P&gt;

&lt;P&gt;Maybe this app can help, but I did not test it.&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3446/#/details"&gt;https://splunkbase.splunk.com/app/3446/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Sep 2018 10:37:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/VirusTotal-API-scan-in-workflow-http-request/m-p/448023#M3984</guid>
      <dc:creator>osakachan</dc:creator>
      <dc:date>2018-09-14T10:37:08Z</dc:date>
    </item>
  </channel>
</rss>

