<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I use Shodan data with Splunk Enterprise Security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220218#M1340</link>
    <description>&lt;P&gt;You will have to interact with shodan's API to pull the information you need and get it into splunk, probably by using a scripted input.&lt;BR /&gt;
Here's a link to Shodan Developer website for more information: &lt;A href="https://developer.shodan.io/"&gt;https://developer.shodan.io/&lt;/A&gt; &lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2016 19:33:27 GMT</pubDate>
    <dc:creator>guarisma</dc:creator>
    <dc:date>2016-10-03T19:33:27Z</dc:date>
    <item>
      <title>How can I use Shodan data with Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220217#M1339</link>
      <description>&lt;P&gt;I am starting to use Enterprise Security to monitor IT security metrics in my enterprise. I am aware of Shodan and have downloaded reports in the past when i did searches for my interfacing IP addresses and to monitor for vulnerabilities. I was recently at .conf2016 and during one of the breakouts, the speaker asked for a show of hands how many have heard of or are using Shodan. So my question is, how i can use Shodan data within Splunk, or more specifically with ES?&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 18:29:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220217#M1339</guid>
      <dc:creator>rickettw</dc:creator>
      <dc:date>2016-10-03T18:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use Shodan data with Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220218#M1340</link>
      <description>&lt;P&gt;You will have to interact with shodan's API to pull the information you need and get it into splunk, probably by using a scripted input.&lt;BR /&gt;
Here's a link to Shodan Developer website for more information: &lt;A href="https://developer.shodan.io/"&gt;https://developer.shodan.io/&lt;/A&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 19:33:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220218#M1340</guid>
      <dc:creator>guarisma</dc:creator>
      <dc:date>2016-10-03T19:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: How can I use Shodan data with Splunk Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220219#M1341</link>
      <description>&lt;P&gt;I can see three ways:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Workflow action: allow users to open the Shodan web UI in the users browser&lt;/LI&gt;
&lt;LI&gt;Adaptive Response Action: get info from Shodan in a way that it can be viewed on Incident Response. To work best with ES, this should be a full Adaptive Response Action (not just a plain Alert Action).&lt;/LI&gt;
&lt;LI&gt;Modular Input: to keep retrieving information for a particular host (if you want to monitor changes in hosts)&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I think number 2 is the most important. I'm seriously thinking of making that alert action. I'll update this comment if I can get time to do it; I don't think it will take me long.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2016 20:37:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-can-I-use-Shodan-data-with-Splunk-Enterprise-Security/m-p/220219#M1341</guid>
      <dc:creator>LukeMurphey</dc:creator>
      <dc:date>2016-10-03T20:37:33Z</dc:date>
    </item>
  </channel>
</rss>

