Splunk Enterprise

Threat Intelligence Feed for Splunk Enterprise

jaridaycock
Explorer

I am struggling to find a post for my answer because the naming for Splunk Enterprise and Enterprise Security is so similar and I am only seeing results for ES..

I want to find a way to add Threat Intelligence feeds into my Splunk Enterprise environment so my organization can eventually move off of the other SIEM we have been using in tandem with Splunk. 

Is this possible with Splunk Enterprise? I know ES has the capability but we are strictly on-prem at the moment and I do not see us moving to it anytime soon.

Any suggestions? Has anyone set these up on prem?

Labels (2)
0 Karma

marnall
Motivator

Splunk Enterprise Security is the official product to handle threat intelligence feeds and other security functions. Enterprise Security can be run on-prem as it is a Splunk app (albeit a large one). Unless you have a compelling reason not to use Enterprise Security, it is the best way to go.

If Enterprise Security is not an option, then you could build your own threat intelligence feed functionality into Splunk Enterprise, but this would take a lot of work. You could pull the threat data into a KV store, then use searches to perform lookups against that KV store. Though these searches can become quite complicated when you are matching certain types of intel (e.g. IP, domain) against various other fields that can contain matching values. 

0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...