Splunk Enterprise Security

How to parse API key to access URL (list) provided by threat intelligence service?

siddh01r
New Member

Hi there,

We now have a service that provides us with a threat intel list. However, if we need to access that URL, we need to parse an API key.

Can someone suggest how I could get this sorted?

Has someone previously done this?

Thanks.

0 Karma

PavelP
Motivator

Hello @siddh01r

first check on Splunkbase if there is an app/add-on for it: https://splunkbase.splunk.com/

Alternatevely, you can access external url using this app: https://splunkbase.splunk.com/app/4146/ written by @jkat54

siddh01r
New Member

Hi There,

Thanks for the recommendation. However, how will i use this app to connect back to my threat intel feed?

what it should do:
1. Use API to connect to external url to retrieve the threat intel feed.
2. intel feed gets downloaded in Splunk Enterprise Security

Thanks in advance.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...