Splunk Search

How do I manually import threat intelligence downloads for internal deployments (no internet)?

thomasaporter
Explorer

Is there anyway to manually import threat intelligence downloads for internal servers (offline from the internet)? Yes, I know that since the system is not connected to the internet, I should not have to worry about external threats. However, we do manually import event data that has come from the outside for our investigations, and I would like to correlate those against threat lists.

0 Karma
1 Solution

sjohnson_splunk
Splunk Employee
Splunk Employee

For OpenIOC and STIX files there is a location on the SH where you can put the files and they will automagically be loaded.

For other sources you can build a lookup file and then add it as a new source via the Web UI.

See this link for the details:

http://docs.splunk.com/Documentation/ES/4.2.0/User/Configureblocklists

View solution in original post

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

For OpenIOC and STIX files there is a location on the SH where you can put the files and they will automagically be loaded.

For other sources you can build a lookup file and then add it as a new source via the Web UI.

See this link for the details:

http://docs.splunk.com/Documentation/ES/4.2.0/User/Configureblocklists

0 Karma

thomasaporter
Explorer

Cool....many thanks for the quick reply.

0 Karma

sjohnson_splunk
Splunk Employee
Splunk Employee

Are you using Splunk Enterprise Security? If so, what version?

0 Karma

thomasaporter
Explorer

Splunk Enterprise 6.4.2 with Splunk App for Enterprise Security 4.1.1

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...