Splunk Enterprise Security

Integration with Obstracts into ES (TAXII 2.1)

0x33kdg
New Member

Hi, I checked Splunkbase for an integration with an intel feed reader we use, Obstract (https://www.obstracts.com/), but was unable to find anything.

They offer a TAXII feed (version 2.1) but I don't think this is supported by ES (this link says only 1.x supported: https://docs.splunk.com/Documentation/ES/latest/RN/Enhancements)? Can anyone confirm?

Of this is the case, is anyone else using Obstracts with Splunk ES?

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Let’s Talk Terraform

If you’re beyond the first-weeks-of-a-startup stage, chances are your application’s architecture is pretty ...

Cloud Platform | Customer Change Announcement: Email Notification is Available For ...

The Notification Team is migrating our email service provider. As the rollout progresses, Splunk has enabled ...

Save the Date: GovSummit Returns Wednesday, December 11th!

Hey there, Splunk Community! Exciting news: Splunk’s GovSummit 2024 is returning to Washington, D.C. on ...