Splunk Enterprise Security

How to implement a two factor authentication (2FA) to collect external feeds from a threat intelligence provider to Splunk Enterprise Security?

sreejith2k2
Explorer

Currently one of the threat intelligence providers gives us an API link to download the threat feeds. But they are planning to change it to the two factor authentication (username, password and certificate). Also, their URL changes everyday.

My Questions:

  1. How can I implement two factor authentication to collect the external feeds from our provider to our Enterprise Security?
  2. If I write a script to generate a URL everyday, how can I make sure that scripts run from Search Head Captain (ours is a SH and Indexer clustered environment) to download the CSV file into the app?
0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

ES does support certificate-based authentication for TAXII feeds, as long as that is what the format is. See instructions here: http://docs.splunk.com/Documentation/ES/4.2.1/User/Configureblocklists#Add_a_TAXII_feed_with_certifi...

I can't comment on #2, but I'd presume that it's something you could work out withe some form of a modular input.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...