All Apps and Add-ons

Threat feed for InfoSec App for SPlunk

crizelle
Explorer

Hi everyone,

Is it possible to add a thread feed on Splunk Enterprise, specifically for InfoSec App? There is no Splunk ES deployed.

Thanks,
Crizelle

Labels (1)

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle,

Out of the box, the current version 1.5.3 of InfoSec app does not use threat feeds.

Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES.

0 Karma

crizelle
Explorer

Hi @igifrin_splunk ,

What do you mean by this? "Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES."

Thanks,
Crizelle

0 Karma

igifrin_splunk
Splunk Employee
Splunk Employee

While InfoSec app does not use threat feeds out of the box, there are other ways to add threat intel and correlate it with the the incoming data like IPs, file hash, domain names, etc.

This can be a starting point:
https://answers.splunk.com/answers/636125/how-to-integrate-threat-intelligence-with-splunk.html

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...