Getting Data In

Splunk and TheHive integration

bil151515
Engager

Hey!
My team is interested in integration of Splunk (especially ES) and TheHive Project products.

The goal is to provide automated sending  Splunk Alerts (Notable Events in case of ES) to TheHive platform for further automatic analysis by Cortex and returning results back to Splunk.

I don't have any experience in stuff like that so I would like to get any ideas of solving this problem.

Maybe anyone have done that before on their project and would like to share any solutions?

Labels (2)

splunkreal
Motivator

Hello @bil151515  we have done it successfully if needed.

* If this helps, please upvote or accept solution if it solved *
0 Karma

Bubbleob
New Member

Can you expand on how your team did it? Ideally with step-by-step methods.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...