- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to parse API key to access URL (list) provided by threat intelligence service?
siddh01r
New Member
05-21-2020
03:55 PM
Hi there,
We now have a service that provides us with a threat intel list. However, if we need to access that URL, we need to parse an API key.
Can someone suggest how I could get this sorted?
Has someone previously done this?
Thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PavelP
Motivator
05-24-2020
04:33 AM
Hello @siddh01r
first check on Splunkbase if there is an app/add-on for it: https://splunkbase.splunk.com/
Alternatevely, you can access external url using this app: https://splunkbase.splunk.com/app/4146/ written by @jkat54
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
siddh01r
New Member
05-24-2020
03:32 PM
Hi There,
Thanks for the recommendation. However, how will i use this app to connect back to my threat intel feed?
what it should do:
1. Use API to connect to external url to retrieve the threat intel feed.
2. intel feed gets downloaded in Splunk Enterprise Security
Thanks in advance.
