Splunk Enterprise Security

Adding manually downloaded Threat Intel file into Splunk ES

Splunkometry88
Explorer

Hi all

I have a threat feed that is available via using an API key only, I could not see any way to add the API key to the threat intel download option?

I can manually create a CURL command to download the file to the right folder but this will not be registered as an intel file.

Thanks

 

0 Karma
1 Solution

starcher
Influencer

Unfortunately There is no custom download like that. You'd need to write some code like python to download the file. Ensure it is in the right csv format. THEN tell ES to monitor ES/Ingest that file.

View solution in original post

starcher
Influencer

Unfortunately There is no custom download like that. You'd need to write some code like python to download the file. Ensure it is in the right csv format. THEN tell ES to monitor ES/Ingest that file.

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...