<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: Can I use a dynamic threat intelligence CSV file as a lookup to compare with firewall IPs? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263545#M1977</link>
    <description>&lt;P&gt;Any update guys ........................................&lt;/P&gt;</description>
    <pubDate>Tue, 06 Dec 2016 11:31:33 GMT</pubDate>
    <dc:creator>sumitkathpal</dc:creator>
    <dc:date>2016-12-06T11:31:33Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Can I use a dynamic threat intelligence CSV file as a lookup to compare with firewall IPs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263544#M1976</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;Here is the scenario:&lt;/P&gt;

&lt;P&gt;Currently we are using custom threat intelligence in Splunk Enterprise Security to download the CSV file (Threat Intelligence from internet) which gets downloaded in path C:\Program Files\Splunk\etc\apps\SA-ThreatIntelligence\local\data\threat_intel\ filename.csv and gets updated every 1 hour.&lt;/P&gt;

&lt;P&gt;Now we need to use this filename.csv (which is dynamic file as it get automatically updated).&lt;/P&gt;

&lt;P&gt;Can I use this dynamic file as a lookup to compare with firewall IP (If yes what are the steps to use the path mentioned above), as we are developing our app for threat intelligence? Or are there other options we can use?&lt;/P&gt;

&lt;P&gt;Thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Happy Splunking &lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 06:45:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263544#M1976</guid>
      <dc:creator>sumitkathpal</dc:creator>
      <dc:date>2016-12-06T06:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Can I use a dynamic threat intelligence CSV file as a lookup to compare with firewall IPs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263545#M1977</link>
      <description>&lt;P&gt;Any update guys ........................................&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 11:31:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263545#M1977</guid>
      <dc:creator>sumitkathpal</dc:creator>
      <dc:date>2016-12-06T11:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Can I use a dynamic threat intelligence CSV file as a lookup to compare with firewall IPs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263546#M1978</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;have you seen/followed this link &lt;A href="http://docs.splunk.com/Documentation/ES/4.5.1/User/Configureblocklists"&gt;http://docs.splunk.com/Documentation/ES/4.5.1/User/Configureblocklists&lt;/A&gt;&lt;BR /&gt;
specifically the "Adding a custom source", choosing a ip type&lt;/P&gt;

&lt;P&gt;and yes, you can use it as a lookup, in ES dashboard, ...&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2016 21:52:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263546#M1978</guid>
      <dc:creator>maraman_splunk</dc:creator>
      <dc:date>2016-12-06T21:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Can I use a dynamic threat intelligence CSV file as a lookup to compare with firewall IPs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263547#M1979</link>
      <description>&lt;P&gt;You could use the entire threat framework to do this.  Make sure the threat intel download settings are correctly pulling into the ip_intel threat collection.  The key is making sure the fields value is configured correctly.  If I had a comma delimited file with description, ip the fields value might look like ip:$2 and the delimiter is ,&lt;/P&gt;

&lt;P&gt;Once the data comes in cleanly to threat artifacts the lookup gen and threat gen will handle the data just like the built in threat intel and the data gets correlated with all logs not just firewall.  Additional refinement could then be done to limit to just firewall.&lt;/P&gt;

&lt;P&gt;There are other ways to solve it but this can leverage all the development that is already in place.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2016 18:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Can-I-use-a-dynamic-threat/m-p/263547#M1979</guid>
      <dc:creator>jstoner_splunk</dc:creator>
      <dc:date>2016-12-08T18:52:40Z</dc:date>
    </item>
  </channel>
</rss>

