Splunk Enterprise Security

stix Threat Intelligence Upload

tmwhitm
New Member

Splunkers,

Once a stix formatted IOC file has been successfully uploaded via Splunk Enterprise Security "Upload Threat Intelligence", I'd like to view the contents of that upload to review the IOCs but I have not been able to see that information, let alone the file listed anywhere. There is an SA-SPLICE application in Splunkbase but that has not been updated since 2015 and doesn't support the latest file formats.

  1. Where in Splunk ES can I view the contents of the uploaded IOC?
  2. How can I confirm the IOC is enabled and providing intel to Splunk ES?

Thank you,

Tom

0 Karma

jaime_ramirez
Communicator

Have you tried this?

https://docs.splunk.com/Documentation/ES/5.3.1/Admin/Verifythreatintel

So in Security Intelligence > Threat Intelligence > Threat Artifacts, you should be able to find your Threat Source with its Intel Source ID.

Later I could elaborate more on the subject.

Hope it helps!!!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...