Hi there, I'd like to have a dedicated threat intel feed which goes to a custom created lookup (non-default), is that even possible?
Hello @heskez Yes it's possible. You can have a custom lookup popped-up and integrate the same local intel - https://docs.splunk.com/Documentation/ES/7.3.2/Admin/Addlocalthreatintel
Please hit Karma, if this helps!