Splunk Enterprise Security

Setup the Threat feed integration in ES

sahiltcs
Path Finder

We are Planning to set up Threat feed integrate in ES, We have installed crowdstrike Intel add on and now need to set up  threat feeds .

Can you Please suggest and guide us is there any specific guide for how to do this with cs threat intel.

 

 

Labels (1)

alonsocaio
Contributor

Hi @sahiltcs,

Are you using the "CrowdStrike Intel Indicator Technical Add-On" to retrieve your threat intel information?

If so, (and if you have not been able to collect intel from CS), you can find the full docs explaining how to send data from CS to Splunk here: https://www.crowdstrike.com/wp-content/uploads/2020/07/CrowdStrike-Falcon-Intel-Indicator-Add-on-Gui...

I am also checking a way on how to integrate the collected intel data with Splunk ES framework.

0 Karma
Get Updates on the Splunk Community!

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...

What's New in Splunk Observability Cloud and Splunk AppDynamics - May 2025

This month, we’re delivering several new innovations in Splunk Observability Cloud and Splunk AppDynamics ...