Splunk Search

How do I manually import threat intelligence downloads for internal deployments (no internet)?

thomasaporter
Explorer

Is there anyway to manually import threat intelligence downloads for internal servers (offline from the internet)? Yes, I know that since the system is not connected to the internet, I should not have to worry about external threats. However, we do manually import event data that has come from the outside for our investigations, and I would like to correlate those against threat lists.

0 Karma
1 Solution

sjohnson_splunk
Splunk Employee
Splunk Employee

For OpenIOC and STIX files there is a location on the SH where you can put the files and they will automagically be loaded.

For other sources you can build a lookup file and then add it as a new source via the Web UI.

See this link for the details:

http://docs.splunk.com/Documentation/ES/4.2.0/User/Configureblocklists

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

For OpenIOC and STIX files there is a location on the SH where you can put the files and they will automagically be loaded.

For other sources you can build a lookup file and then add it as a new source via the Web UI.

See this link for the details:

http://docs.splunk.com/Documentation/ES/4.2.0/User/Configureblocklists

0 Karma

thomasaporter
Explorer

Cool....many thanks for the quick reply.

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Are you using Splunk Enterprise Security? If so, what version?

0 Karma

thomasaporter
Explorer

Splunk Enterprise 6.4.2 with Splunk App for Enterprise Security 4.1.1

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Word Search

This challenge was first posted on Slack #puzzles channelThis puzzle is based on a letter grid containing ...

[Puzzles] Solve, Learn, Repeat: Advent of Code - Day 4

Advent of CodeIn order to participate in these challenges, you will need to register with the Advent of Code ...

GA: S3 Promote for Historical Data Ingestion in Splunk Cloud

Ingest Historical S3 Data On-Demand: Announcing the General Availability of S3 Promote We’re excited to share ...