Splunk Search

Is there a way to create a lookup table that contains Threat Intelligence data so I can correlate searches against it?

Makinde
New Member

My question is in two parts,

Is there a special way to create a Lookup table that contains Threat Intelligence such that I can correlate searches against it? I am interested in just an IP address field and a Domain Field. Assuming I had both fields in my CSV lookup table, what will my correlation search look like so that I can identify when I have traffic in my network that matches any IP address or Domain in my lookup table?

Secondly is there a way to automatically download Threat Intelligence from other sources? I am interested in the CCIRC, TAXII, Facebook, and/or Malware domain threat lists. Is there an App that can do this? I don't want to have to download Splunk Enterprise Security to do this.

Thanks

0 Karma

jsanchez_splunk
Splunk Employee
Splunk Employee

You may want to check out Splice. The feed is stored in MongoDB.

https://splunkbase.splunk.com/app/2637/

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...