Getting Data In

How to integrate threat intel platform in splunk (OpenCTI)

splk_user
Path Finder

Hi!

i want to integrate OpenCTI intel feeds to splunk and i don't find any Add-on for this integration .

OpenCTI provide a connector for this connection but what is the configuration that i need to provide in splunk to receive the feeds .

Can you Please suggest if there is any specific guide for how to do this with opencti ;

Thank you

0 Karma

caiosalonso
Path Finder

Hi @splk_user,

Could you please provide the link to the connector?

Also, do you want to integrate the intel feeds to Spunk Core or to Splunk Enterprise Security?

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...