Getting Data In

threat_intelligence_manager as input in the inputs.conf file

kausar
Path Finder

I see the following stanza in my SplunkEnterpriseSecurity app's inputs.conf file. (added by splunk professional)

[threat_intelligence_manager://]
...

What is that and where is it coming from? I can't find any details on any this input in the inputsconf documentation. https://docs.splunk.com/Documentation/Splunk/6.5.3/Admin/Inputsconf. Where would I find stuffs to read further about it?

Tags (1)
0 Karma
1 Solution

llee_splunk
Splunk Employee
Splunk Employee

That stanza is managed by the threat_intelligence_manager.py modular input. You can read more on the Threat Intelligence framework in Splunk ES here: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBC

View solution in original post

llee_splunk
Splunk Employee
Splunk Employee

That stanza is managed by the threat_intelligence_manager.py modular input. You can read more on the Threat Intelligence framework in Splunk ES here: http://dev.splunk.com/view/enterprise-security/SP-CAAAFBC

Get Updates on the Splunk Community!

Celebrating Fast Lane: 2025 Authorized Learning Partner of the Year

At .conf25, Splunk proudly recognized Fast Lane as the 2025 Authorized Learning Partner of the Year. This ...

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...