All Apps and Add-ons

Threat feed for InfoSec App for SPlunk

crizelle
Explorer

Hi everyone,

Is it possible to add a thread feed on Splunk Enterprise, specifically for InfoSec App? There is no Splunk ES deployed.

Thanks,
Crizelle

Labels (1)

igifrin_splunk
Splunk Employee
Splunk Employee

Hi @crizelle,

Out of the box, the current version 1.5.3 of InfoSec app does not use threat feeds.

Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES.

0 Karma

crizelle
Explorer

Hi @igifrin_splunk ,

What do you mean by this? "Others may want to chime in what they have done with threat intel feeds in Splunk Enterprise before going with ES."

Thanks,
Crizelle

0 Karma

igifrin_splunk
Splunk Employee
Splunk Employee

While InfoSec app does not use threat feeds out of the box, there are other ways to add threat intel and correlate it with the the incoming data like IPs, file hash, domain names, etc.

This can be a starting point:
https://answers.splunk.com/answers/636125/how-to-integrate-threat-intelligence-with-splunk.html

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...