All Apps and Add-ons

Threat feed for InfoSec App for SPlunk

crizelle
Explorer

Hi everyone,

Is it possible to add a thread feed on Splunk Enterprise, specifically for InfoSec App? There is no Splunk ES deployed.

Thanks,
Crizelle

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle,

Out of the box, the current version 1.5.3 of InfoSec app does not use threat feeds.

Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES.

0 Karma

crizelle
Explorer

Hi @igifrin_splunk ,

What do you mean by this? "Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES."

Thanks,
Crizelle

0 Karma

igifrin_splunk
Splunk Employee
Splunk Employee

While InfoSec app does not use threat feeds out of the box, there are other ways to add threat intel and correlate it with the the incoming data like IPs, file hash, domain names, etc.

This can be a starting point:
https://answers.splunk.com/answers/636125/how-to-integrate-threat-intelligence-with-splunk.html

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...