Splunk Enterprise Security

stix Threat Intelligence Upload

tmwhitm
New Member

Splunkers,

Once a stix formatted IOC file has been successfully uploaded via Splunk Enterprise Security "Upload Threat Intelligence", I'd like to view the contents of that upload to review the IOCs but I have not been able to see that information, let alone the file listed anywhere. There is an SA-SPLICE application in Splunkbase but that has not been updated since 2015 and doesn't support the latest file formats.

  1. Where in Splunk ES can I view the contents of the uploaded IOC?
  2. How can I confirm the IOC is enabled and providing intel to Splunk ES?

Thank you,

Tom

0 Karma

jaime_ramirez
Communicator

Have you tried this?

https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Verifythreatintel

So in Security Intelligence > Threat Intelligence > Threat Artifacts, you should be able to find your Threat Source with its Intel Source ID.

Later I could elaborate more on the subject.

Hope it helps!!!

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...