All Apps and Add-ons

Is it possible to set up the SA-SPLICE app MongDB connection to point directly to the SoltraEdge MongoDB?

Ovi
Path Finder

I am wondering if it would be possible to just set up the SPLICE app MongoDB connection to point directly to the SoltraEdge MongoDB? Basically let Soltra do all the TAXII work and have Splunk query directly the Soltra DB and avoid having to set up and maintain a separate MongoDB instance.
Would that be possible/advisable or it will not work and why?
Thanks

Tags (2)
0 Karma
1 Solution

cleroux_splunk
Splunk Employee
Splunk Employee

Short answer, no.

Soltra Edge has its own schema and Splice do not know anything about it. That's exactly why protocol such as TAXII have been developed. What you can do is having your Soltra Edge collecting one or multiple TAXII feeds and then Splice or Splunk Enterprise Security will collect the aggregated results through TAXII.

Enterprise Security leverage the KV Store to store IOCs so you don't have to maintain a separate mongo instance (and they are no plans for Splice to migrate to the KV Store at the moment).

View solution in original post

cleroux_splunk
Splunk Employee
Splunk Employee

Short answer, no.

Soltra Edge has its own schema and Splice do not know anything about it. That's exactly why protocol such as TAXII have been developed. What you can do is having your Soltra Edge collecting one or multiple TAXII feeds and then Splice or Splunk Enterprise Security will collect the aggregated results through TAXII.

Enterprise Security leverage the KV Store to store IOCs so you don't have to maintain a separate mongo instance (and they are no plans for Splice to migrate to the KV Store at the moment).

Ovi
Path Finder

Thanks Cedric. It makes sense.
I just wanted to confirm my understanding before putting forward the solution design

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...

Data Persistence in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. What happens if the OpenTelemetry collector ...

Thanks for the Memories! Splunk University, .conf25, and our Community

Thank you to everyone in the Splunk Community who joined us for .conf25, which kicked off with our iconic ...