Infoblox BloxOne Threat Defense

Splunk Community

Infoblox BloxOne Threat Defense

Infoblox BloxOne Threat Defense
This application allows to: - acquire ActiveTrust / BloxOne Threat Defense Cloud logs using REST API - filter it efficiently with full drill down support based on the time, threat property, threat class, source IP, domain name, query type and much more - summarize hits by IOCs - get IOCs context from Infoblox Dossier threat intelligence - prioritize hits based on context - search and pivot Threat Intelligence based on the IOCs matched in DNS traffic - report on BloxOne endpoints deployment Mandatory requires ActiveTrust / BloxOne Threat Defense Optionally requires Dossier for threat intelligence
0 topics and 0 replies mentioned Infoblox BloxOne Threat Defense in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.