Splunk Enterprise Security

What is "Malware Domains threatlist" in Splunk Enterprise Security?

Ananta
New Member

Hi All,

We are planning to upgrade Splunk ES from 6.2 to 7.0.1. In Release Notes of 7.0.1 deprecated features, its mentioned like below.

No support for Malware Domains threatlist The Malware Domains threatlist is not supported in Enterprise security version 6.5.0 or higher.

 

 Is it any kind of lookup definition as mentioned in below link?

https://community.splunk.com/t5/Security/Add-domains-to-threat-lists/td-p/116392

Or its related to below dashboard in Enterprise Security Suit?

SplunkEnterpriseSecuritySuite/Security Intelligence/Threat Intelligence/Threat Activity/Threat Group/Threat Group (malwaretriage)

Basically, I am not able to find out which feature is going to deprecate or remove. Please su

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Dashboard Challenge and Watch the .conf24 Global Broadcast!

The Splunk Community Dashboard Challenge is still happening, and it's not too late to enter for the week of ...