Splunk Enterprise Security

Splunk Enterprise Security: How to correlate IOCs within a lookup file with web traffic captured by Splunk?

tyrone_osilesi7
Explorer

Hi,

I have a lookup file tracking IOCs from multiple sources. I'm looking for a way to take this list and ideally generate a notable event in Splunk Enterprise Security if ever web logs show that a user attempted to navigate to an IP or domain within the list. Now that we have this data we need to put it to use. Any suggestions?

0 Karma
1 Solution

starcher
Influencer

http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists

See the section Upload a custom CSV file of threat intelligence

View solution in original post

starcher
Influencer

http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists

See the section Upload a custom CSV file of threat intelligence

Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...