Splunk Search

Is there a way to create a lookup table that contains Threat Intelligence data so I can correlate searches against it?

New Member

My question is in two parts,

Is there a special way to create a Lookup table that contains Threat Intelligence such that I can correlate searches against it? I am interested in just an IP address field and a Domain Field. Assuming I had both fields in my CSV lookup table, what will my correlation search look like so that I can identify when I have traffic in my network that matches any IP address or Domain in my lookup table?

Secondly is there a way to automatically download Threat Intelligence from other sources? I am interested in the CCIRC, TAXII, Facebook, and/or Malware domain threat lists. Is there an App that can do this? I don't want to have to download Splunk Enterprise Security to do this.

Thanks

0 Karma

Splunk Employee
Splunk Employee

You may want to check out Splice. The feed is stored in MongoDB.

https://splunkbase.splunk.com/app/2637/

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!