All Apps and Add-ons

Has anyone used Palo Alto Networks MineMeld to send logs to Splunk? Can you help with configuration?

mrtolu6
Path Finder

Has anyone ever sent intel to Splunk using MineMeld? If so how? I currently have access to MineMeld, but I was looking for away to set up the config to send the intel to Splunk.

0 Karma
1 Solution

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

View solution in original post

gmellini
Engager

I wrote a series of blog posts on Threat Intelligence automation using MineMeld and Splunk
You can find here
https://scubarda.wordpress.com/category/threat-intelligence/

Some note:

  1. on post 1 I show the architecture
  2. on post 2 howto write custom prototypes and IoC integration with our SOC Splunk application. This is the near real time engine we are using to check IoC access
  3. on post 3 howto create a STIX/TAXII output miner to export Ioc
  4. on post 4 how I integrate the IoC events into Splunk to analyze it to see some stats. I also wrote the simple TA to parse the events and a small app to check data

Hope this is useful
Giovanni

Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...