<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to integrate the Threat intelligence feeds from ThreatConnect App for Splunk Enterprise into the Splunk Enteprise Security app? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-integrate-the-Threat-intelligence-feeds-from/m-p/244782#M1706</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There is an app for threat connect (&lt;A href="https://splunkbase.splunk.com/app/1893/"&gt;https://splunkbase.splunk.com/app/1893/&lt;/A&gt; ), but it does not integrate into Splunk Enterprise Security out of the box. Has anyone managed to integrate the Threat intelligence feeds from Threat Connect into Splunk ES?&lt;/P&gt;

&lt;P&gt;Since ES already does the work for matching incoming data against the Threat intelligence feeds, I would like to be able to avoid having to install 2 splunk apps and just use ES to gain most value from both ES and Threat Connect.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2015 19:57:20 GMT</pubDate>
    <dc:creator>anandhim</dc:creator>
    <dc:date>2015-11-24T19:57:20Z</dc:date>
    <item>
      <title>How to integrate the Threat intelligence feeds from ThreatConnect App for Splunk Enterprise into the Splunk Enteprise Security app?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-integrate-the-Threat-intelligence-feeds-from/m-p/244782#M1706</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There is an app for threat connect (&lt;A href="https://splunkbase.splunk.com/app/1893/"&gt;https://splunkbase.splunk.com/app/1893/&lt;/A&gt; ), but it does not integrate into Splunk Enterprise Security out of the box. Has anyone managed to integrate the Threat intelligence feeds from Threat Connect into Splunk ES?&lt;/P&gt;

&lt;P&gt;Since ES already does the work for matching incoming data against the Threat intelligence feeds, I would like to be able to avoid having to install 2 splunk apps and just use ES to gain most value from both ES and Threat Connect.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 19:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-integrate-the-Threat-intelligence-feeds-from/m-p/244782#M1706</guid>
      <dc:creator>anandhim</dc:creator>
      <dc:date>2015-11-24T19:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to integrate the Threat intelligence feeds from ThreatConnect App for Splunk Enterprise into the Splunk Enteprise Security app?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-integrate-the-Threat-intelligence-feeds-from/m-p/244783#M1707</link>
      <description>&lt;P&gt;ES is not supported when other apps are installed.&lt;BR /&gt;
So you will want to avoid adding any non-Splunk Certified app add-ons to the ES installation.&lt;/P&gt;

&lt;P&gt;That being said, you can download the ThreatConnect integration and inspect the app for content that might want to add.&lt;/P&gt;

&lt;P&gt;In the latest versions of ES, the threat intelligence setup is a wizard that you go through. What you want to do is find what data feed source the Threat Connect app looks at and mirror that in your own configuration by Configuring a Threat list in ES. &lt;/P&gt;

&lt;P&gt;Check out how to do that here.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/Configureblocklists"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/Configureblocklists&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;TL:DR; don't install a new app e.g. 1893, instead look at the app configs to find out the threat feed source and use the above url to set it up in ES.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2015 20:26:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-integrate-the-Threat-intelligence-feeds-from/m-p/244783#M1707</guid>
      <dc:creator>mcronkrite</dc:creator>
      <dc:date>2015-11-24T20:26:46Z</dc:date>
    </item>
  </channel>
</rss>

