Splunk Enterprise Security

How to view data from Threat intel collections?

neerajs_81
Builder

Hello, Like any other ES user, we have threat intel feeds configured that came along with box.  How can i view the actual data of this threat intel feed ?  

For example:   Lets take the cisco_top_one_million_sites OR  emerging_threats_ip_blocklist  sources.

neerajs_81_0-1659069546287.png

All of these 4 commands error out.   Well,  how can i find what is being downloaded ? How to view these collection s ?

| inputintelligence emerging_threats_ip_blocklist
OR
| inputlookup emerging_threats_ip_blocklist
OR
| inputintelligence cisco_top_one_million_sites
OR 
| inputlookup cisco_top_one_million_sites

 

Labels (1)
0 Karma

xeaon
Explorer

Hey! There is a dashboard for all your threat artifacts in

Security Intelligence -> Threat Intelligence -> Threat Artifacts

 

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...