All Apps and Add-ons

Splunk MISP42 sighting: How to update the sighting of an attribute in connected MISP instance?

schimpy
New Member

Hello folks,

Has anyone of you made it work that you somehow update the sighting of an attribute in connected MISP instance?

I have my MISP integrated to Splunk, IoC are being downloaded to TI framework. Based on this some correlation searches that are scheduled, TI-based notables triggers

I am looking for a way how to get the feedback about TP/FP back to MISP.

I am using MISP42Splunk app, which has an adaptive response action "Alert for sighting MISP attribute(s)"  but I cannot make it work.

I was also trying to do it via some in-build MISP command without any success.

Do you guy have implemented this feature of do you know some way to do it?

Thanks!

Labels (3)
Tags (2)
0 Karma

riccardo_spl
Explorer

Never used this adaptive response type, did you get any success?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...