Getting Data In

How to integrate threat intel platform in splunk (OpenCTI)

splk_user
Path Finder

Hi!

i want to integrate OpenCTI intel feeds to splunk and i don't find any Add-on for this integration .

OpenCTI provide a connector for this connection but what is the configuration that i need to provide in splunk to receive the feeds .

Can you Please suggest if there is any specific guide for how to do this with opencti ;

Thank you

0 Karma

caiosalonso
Path Finder

Hi @splk_user,

Could you please provide the link to the connector?

Also, do you want to integrate the intel feeds to Spunk Core or to Splunk Enterprise Security?

0 Karma
Get Updates on the Splunk Community!

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...

Splunkbase | Splunk Dashboard Examples App for SimpleXML End of Life

The Splunk Dashboard Examples App for SimpleXML will reach end of support on Dec 19, 2024, after which no new ...