In our Splunk App for Enterprise Security server, I want to add a local threat list that lists URLs to watch through the app and populate the list with the threats. We have prebuilt lists on our server, but I don't really know how to build them. I can see them in data enrichment on the app, however I don't know of a way to test them out. Sorry I'm a bit new at Splunk. Just started two weeks ago. Still reading basic documentation.
You should have a look by here: http://docs.splunk.com/Documentation/ES/3.3.0/Install/Configureblocklists#Add_a_file_based_threat_so...