All Apps and Add-ons

Has anyone used Palo Alto Networks MineMeld to send logs to Splunk? Can you help with configuration?

mrtolu6
Path Finder

Has anyone ever sent intel to Splunk using MineMeld? If so how? I currently have access to MineMeld, but I was looking for away to set up the config to send the intel to Splunk.

0 Karma
1 Solution

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...