Splunk Enterprise Security

How to parse API key to access URL (list) provided by threat intelligence service?

siddh01r
New Member

Hi there,

We now have a service that provides us with a threat intel list. However, if we need to access that URL, we need to parse an API key.

Can someone suggest how I could get this sorted?

Has someone previously done this?

Thanks.

0 Karma

PavelP
Motivator

Hello @siddh01r

first check on Splunkbase if there is an app/add-on for it: https://splunkbase.splunk.com/

Alternatevely, you can access external url using this app: https://splunkbase.splunk.com/app/4146/ written by @jkat54

siddh01r
New Member

Hi There,

Thanks for the recommendation. However, how will i use this app to connect back to my threat intel feed?

what it should do:
1. Use API to connect to external url to retrieve the threat intel feed.
2. intel feed gets downloaded in Splunk Enterprise Security

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...