All Apps and Add-ons

Threat feed for InfoSec App for SPlunk

crizelle
Explorer

Hi everyone,

Is it possible to add a thread feed on Splunk Enterprise, specifically for InfoSec App? There is no Splunk ES deployed.

Thanks,
Crizelle

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle,

Out of the box, the current version 1.5.3 of InfoSec app does not use threat feeds.

Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES.

0 Karma

crizelle
Explorer

Hi @igifrin_splunk ,

What do you mean by this? "Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES."

Thanks,
Crizelle

0 Karma

igifrin_splunk
Splunk Employee
Splunk Employee

While InfoSec app does not use threat feeds out of the box, there are other ways to add threat intel and correlate it with the the incoming data like IPs, file hash, domain names, etc.

This can be a starting point:
https://answers.splunk.com/answers/636125/how-to-integrate-threat-intelligence-with-splunk.html

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...