Splunk Enterprise Security

IBM X-force Threat Intelligence feed integration with Splunk ES

ayushchoudhary
Path Finder

Can some one please help if you have any document on how to integrate the IBM X-force Threat intelligence feed with Splunk ES.

0 Karma

vikashjha
New Member

were you able to integrate this threat feed with splunk?

0 Karma

kchamplin_splun
Splunk Employee
Splunk Employee

ES has a threat intel framework you can use to onboard the data:
https://dev.splunk.com/enterprise/docs/developapps/enterprisesecurity/threatintelligenceframework/

I'm not entirely familiar with how IBM exposes their threat feed, but the ES framework is very robust and should be pretty straightforward to do.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...