Splunk Enterprise Security

Enterprise Security- How to Add Threat Intelligence Feed using remote API?

qq-stan
Engager

Splunk ES documentation https://docs.splunk.com/Documentation/ES/7.1.1/Admin/Downloadthreatfeed#Add_a_URL-based_threat_sourc...  describes how to Add a URL-based threat source and it seems work even with credential using POST. What if I have to use API Key instead of credentials? How to download Threat Intelligence from a remote API using API Keys? From  MCAP https://mcap.cisecurity.org/ for instance.

Thank you for your time in advance.

Labels (1)
0 Karma

qq-stan
Engager

Thank you, @meetmshah 

"Cisco Threat Grid Add-On" is not exactly what I am looking for.  My objective is to feed ES with the MCAP threat intelligence from https://mcap.cisecurity.org/ using its API key/token, if that possible.

Thank you for your response.

0 Karma

meetmshah
Contributor

Hello @qq-stan, Have you checked https://splunkbase.splunk.com/app/4251 for MCAP?

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...