Splunk Cloud Platform

is splunk cloud or splunk enterprise capable of being a stix/taxii client?

trojan_81
Path Finder

Hello Splunk Experts,

My organization has splunk cloud and enterprise security. 

I was wondering if Splunk is capable of acting as a stix/taxii client so that I can enroll with a threat intelligence provider and have those feeds come directly into splunk.  I know splunk has a way for me to upload stix/taxii files but that's manual. 

 

Labels (1)
0 Karma

trojan_81
Path Finder

To be clear, I am asking if splunk is able to act as a TAXII client so that it can retrieve STIX formatted threat intelligence automatically. Or will this require a 3rd party service like a Threatconnect or Threatstream?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...