All Apps and Add-ons

Has anyone used Palo Alto Networks MineMeld to send logs to Splunk? Can you help with configuration?

mrtolu6
Path Finder

Has anyone ever sent intel to Splunk using MineMeld? If so how? I currently have access to MineMeld, but I was looking for away to set up the config to send the intel to Splunk.

0 Karma
1 Solution

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...