Splunk Enterprise Security

How to view data from Threat intel collections?

neerajs_81
Builder

Hello, Like any other ES user, we have threat intel feeds configured that came along with box.  How can i view the actual data of this threat intel feed ?  

For example:   Lets take the cisco_top_one_million_sites OR  emerging_threats_ip_blocklist  sources.

neerajs_81_0-1659069546287.png

All of these 4 commands error out.   Well,  how can i find what is being downloaded ? How to view these collection s ?

| inputintelligence emerging_threats_ip_blocklist
OR
| inputlookup emerging_threats_ip_blocklist
OR
| inputintelligence cisco_top_one_million_sites
OR 
| inputlookup cisco_top_one_million_sites

 

Labels (1)
0 Karma

xeaon
Explorer

Hey! There is a dashboard for all your threat artifacts in

Security Intelligence -> Threat Intelligence -> Threat Artifacts

 

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...