<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk buildin intelligence feed in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440576#M5924</link>
    <description>&lt;P&gt;Please do not accept your own answer. Accept Lakshman's answer, so that he gets awarded the karma for correctly answering your question. Thank you!&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2019 22:15:03 GMT</pubDate>
    <dc:creator>smoir_splunk</dc:creator>
    <dc:date>2019-08-08T22:15:03Z</dc:date>
    <item>
      <title>Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440572#M5920</link>
      <description>&lt;P&gt;Dear Splunkers,&lt;/P&gt;

&lt;P&gt;Does Splunk enterprise security come with any threat intelligence feed that is solely provided by Splunk?.&lt;/P&gt;

&lt;P&gt;Or does Splunk provide any threat intelligence feed?.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 13:59:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440572#M5920</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-08-08T13:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440573#M5921</link>
      <description>&lt;P&gt;Yes, Splunk comes with threat intel and also allows you to add your own. Look at step 1 and 2 in &lt;A href="https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Addthreatintel"&gt;https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Addthreatintel&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 15:14:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440573#M5921</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-08-08T15:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440574#M5922</link>
      <description>&lt;P&gt;Hi lakshman,&lt;/P&gt;

&lt;P&gt;We receive Phishing attack feeds (which we need to manually upload every week) and i am planning to use email_intel as the threat feed. But we have the following header fields Bitcoin address, File names, Terminated Process and Email Subject etc. &lt;/P&gt;

&lt;P&gt;For email_intel as per Splunk, we need to use description,src_user,subject,weight. &lt;/P&gt;

&lt;P&gt;Is it okay to create this a email_intel or do i have to use a different one?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:40:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440574#M5922</guid>
      <dc:creator>spectrum2035</dc:creator>
      <dc:date>2020-09-30T01:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440575#M5923</link>
      <description>&lt;P&gt;Thanks brother for prompt response.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 17:29:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440575#M5923</guid>
      <dc:creator>hariskhan</dc:creator>
      <dc:date>2019-08-08T17:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440576#M5924</link>
      <description>&lt;P&gt;Please do not accept your own answer. Accept Lakshman's answer, so that he gets awarded the karma for correctly answering your question. Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 22:15:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440576#M5924</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2019-08-08T22:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk buildin intelligence feed</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440577#M5925</link>
      <description>&lt;P&gt;Splunk Enterprise Security includes connections to open source threat intelligence feeds, but it is not a threat intelligence collector/provider like an ISAC might be, or like VERIS or Facebook Threat Exchange. It allows you to aggregate threat intelligence, but Splunk the company does not collect any as a service.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 22:15:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-buildin-intelligence-feed/m-p/440577#M5925</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2019-08-08T22:15:42Z</dc:date>
    </item>
  </channel>
</rss>

