All Apps and Add-ons

Has anyone used Palo Alto Networks MineMeld to send logs to Splunk? Can you help with configuration?

mrtolu6
Path Finder

Has anyone ever sent intel to Splunk using MineMeld? If so how? I currently have access to MineMeld, but I was looking for away to set up the config to send the intel to Splunk.

0 Karma
1 Solution

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...