Splunk Enterprise Security

How to parse API key to access URL (list) provided by threat intelligence service?

siddh01r
New Member

Hi there,

We now have a service that provides us with a threat intel list. However, if we need to access that URL, we need to parse an API key.

Can someone suggest how I could get this sorted?

Has someone previously done this?

Thanks.

Labels (1)
0 Karma

PavelP
Motivator

Hello @siddh01r

first check on Splunkbase if there is an app/add-on for it: https://splunkbase.splunk.com/

Alternatevely, you can access external url using this app: https://splunkbase.splunk.com/app/4146/ written by @jkat54

siddh01r
New Member

Hi There,

Thanks for the recommendation. However, how will i use this app to connect back to my threat intel feed?

what it should do:
1. Use API to connect to external url to retrieve the threat intel feed.
2. intel feed gets downloaded in Splunk Enterprise Security

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Observability Unveiled: Navigating OpenTelemetry's Framework and Deployment Options

Observability Unveiled: Navigating OpenTelemetry's Framework and Deployment Options A recent Tech Talk, ...

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...