Not intending to drag up an old topic, but I'm interested in knowing what "taxii2client" is referencing? It's my understanding that the latest versions of Splunk ES do not natively support TAXII v2. Is this in reference to a custom install of taxii2client from OASIS Open onto a Splunk ES instance, and somehow configuring it to work with feed ingestion to the Intelligence framework/collections? I've recently been trying to identify the best supported solution for STIX 2.1 feeds, which require TAXII 2 communications, into Splunk ES, so I'm curious about the points made in this discussion and what options have been working.
... View more