All Apps and Add-ons

Threat feed for InfoSec App for SPlunk

crizelle
Explorer

Hi everyone,

Is it possible to add a thread feed on Splunk Enterprise, specifically for InfoSec App? There is no Splunk ES deployed.

Thanks,
Crizelle

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle,

Out of the box, the current version 1.5.3 of InfoSec app does not use threat feeds.

Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES.

0 Karma

crizelle
Explorer

Hi @igifrin_splunk ,

What do you mean by this? "Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES."

Thanks,
Crizelle

0 Karma

igifrin_splunk
Splunk Employee
Splunk Employee

While InfoSec app does not use threat feeds out of the box, there are other ways to add threat intel and correlate it with the the incoming data like IPs, file hash, domain names, etc.

This can be a starting point:
https://answers.splunk.com/answers/636125/how-to-integrate-threat-intelligence-with-splunk.html

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...