Splunk Search

Is there a way to create a lookup table that contains Threat Intelligence data so I can correlate searches against it?

Makinde
New Member

My question is in two parts,

Is there a special way to create a Lookup table that contains Threat Intelligence such that I can correlate searches against it? I am interested in just an IP address field and a Domain Field. Assuming I had both fields in my CSV lookup table, what will my correlation search look like so that I can identify when I have traffic in my network that matches any IP address or Domain in my lookup table?

Secondly is there a way to automatically download Threat Intelligence from other sources? I am interested in the CCIRC, TAXII, Facebook, and/or Malware domain threat lists. Is there an App that can do this? I don't want to have to download Splunk Enterprise Security to do this.

Thanks

0 Karma

jsanchez_splunk
Splunk Employee
Splunk Employee

You may want to check out Splice. The feed is stored in MongoDB.

https://splunkbase.splunk.com/app/2637/

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...