<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: threat intelligence in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673754#M11871</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Should I expect that the threat intelligence that is streaming in is being ran against the events in my environment automatically?&amp;nbsp;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I would not expect that, most vendors don't intergrade with the Splunk ES threat intel framework they just make the TI data available in Splunk via a lookup file or by putting it in a index. If you want to be sure the TI info is flowing into the threat intel framework I suggest you add the data there either by revering to the app created lookup (if any), by creating your own lookup from the indexed data or by adding a TAXII/STIX feed.&lt;/P&gt;&lt;P&gt;See for more info:&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/UCE/Prioritized_Actions/Threat_intelligence/Using_threat_intelligence_in_Splunk_Enterprise_Security" target="_blank" rel="noopener"&gt;Splunk Latern&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/7.3.0/Admin/Addthreatintel" target="_blank" rel="noopener"&gt;Splunk Docs&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Jan 2024 09:58:24 GMT</pubDate>
    <dc:creator>aholzel</dc:creator>
    <dc:date>2024-01-10T09:58:24Z</dc:date>
    <item>
      <title>threat intelligence</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673449#M11868</link>
      <description>&lt;P&gt;I am subscribed to a 3rd party threat intelligence called Group-IB.&amp;nbsp; I have the Group-IBapp for splunk installed on my search head.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is in regards to tuning as I have done very little to none. Should I expect that the threat intelligence that is streaming in is being ran against the events in my environment automatically? Assuming the threat intelligence is CIM compliant, should I expect that my Enterprise Security will make a notable event if there is a match?&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jan 2024 13:13:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673449#M11868</guid>
      <dc:creator>mohad</dc:creator>
      <dc:date>2024-01-07T13:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: threat intelligence</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673754#M11871</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;Should I expect that the threat intelligence that is streaming in is being ran against the events in my environment automatically?&amp;nbsp;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;I would not expect that, most vendors don't intergrade with the Splunk ES threat intel framework they just make the TI data available in Splunk via a lookup file or by putting it in a index. If you want to be sure the TI info is flowing into the threat intel framework I suggest you add the data there either by revering to the app created lookup (if any), by creating your own lookup from the indexed data or by adding a TAXII/STIX feed.&lt;/P&gt;&lt;P&gt;See for more info:&lt;BR /&gt;&lt;A href="https://lantern.splunk.com/Security/UCE/Prioritized_Actions/Threat_intelligence/Using_threat_intelligence_in_Splunk_Enterprise_Security" target="_blank" rel="noopener"&gt;Splunk Latern&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/7.3.0/Admin/Addthreatintel" target="_blank" rel="noopener"&gt;Splunk Docs&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 09:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673754#M11871</guid>
      <dc:creator>aholzel</dc:creator>
      <dc:date>2024-01-10T09:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: threat intelligence</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673927#M11874</link>
      <description>&lt;P&gt;thank you for your help&lt;/P&gt;&lt;P&gt;can you help in how to&amp;nbsp;&lt;SPAN&gt;create&amp;nbsp; my own lookup from the indexed&amp;nbsp;IT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jan 2024 11:15:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/threat-intelligence/m-p/673927#M11874</guid>
      <dc:creator>mohad</dc:creator>
      <dc:date>2024-01-11T11:15:54Z</dc:date>
    </item>
  </channel>
</rss>

