Archive

Has anyone used Palo Alto Networks MineMeld to send logs to Splunk? Can you help with configuration?

Path Finder

Has anyone ever sent intel to Splunk using MineMeld? If so how? I currently have access to MineMeld, but I was looking for away to set up the config to send the intel to Splunk.

0 Karma
1 Solution

Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post

Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post