All Apps and Add-ons

Which Splunk Threat Intelligence app in splunkbase lets us add our own IoC/ data for searching?

swapsplunk236
Explorer

Hi, Can somebody suggest a threat intel app available (apary from ES) which allows us to add our IOCs for searching matching events.

Thanks.

0 Karma
1 Solution

ekost
Splunk Employee
Splunk Employee

There appear to be several options on Splunkbase, but it'll depend upon the format your IOCs are created in. One that stands out is SA-Splice for ingesting STIX 1.1, CybOX 2.1, OpenIOC 1.0 and 1.1 formats. A quick search on Splunkbase for "IOC" should give you plenty to work with.

Good luck!

View solution in original post

ekost
Splunk Employee
Splunk Employee

There appear to be several options on Splunkbase, but it'll depend upon the format your IOCs are created in. One that stands out is SA-Splice for ingesting STIX 1.1, CybOX 2.1, OpenIOC 1.0 and 1.1 formats. A quick search on Splunkbase for "IOC" should give you plenty to work with.

Good luck!

*NEW* Splunk Love Promo!
Snag a $25 Visa Gift Card for Giving Your Review!

It's another Splunk Love Special! For a limited time, you can review one of our select Splunk products through Gartner Peer Insights and receive a $25 Visa gift card!

Review:





Or Learn More in Our Blog >>