Splunk Enterprise Security

Splunk buildin intelligence feed

hariskhan
Explorer

Dear Splunkers,

Does Splunk enterprise security come with any threat intelligence feed that is solely provided by Splunk?.

Or does Splunk provide any threat intelligence feed?.

0 Karma
1 Solution

smoir_splunk
Splunk Employee
Splunk Employee

Splunk Enterprise Security includes connections to open source threat intelligence feeds, but it is not a threat intelligence collector/provider like an ISAC might be, or like VERIS or Facebook Threat Exchange. It allows you to aggregate threat intelligence, but Splunk the company does not collect any as a service.

View solution in original post

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Splunk Enterprise Security includes connections to open source threat intelligence feeds, but it is not a threat intelligence collector/provider like an ISAC might be, or like VERIS or Facebook Threat Exchange. It allows you to aggregate threat intelligence, but Splunk the company does not collect any as a service.

0 Karma

hariskhan
Explorer

Thanks brother for prompt response.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Please do not accept your own answer. Accept Lakshman's answer, so that he gets awarded the karma for correctly answering your question. Thank you!

0 Karma

lakshman239
Influencer

Yes, Splunk comes with threat intel and also allows you to add your own. Look at step 1 and 2 in https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Addthreatintel

spectrum2035
Explorer

Hi lakshman,

We receive Phishing attack feeds (which we need to manually upload every week) and i am planning to use email_intel as the threat feed. But we have the following header fields Bitcoin address, File names, Terminated Process and Email Subject etc.

For email_intel as per Splunk, we need to use description,src_user,subject,weight.

Is it okay to create this a email_intel or do i have to use a different one?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Telemetry Pipeline Management

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...