The ET Splunk Technical Add-on (ET-TA) seamlessly integrates the acclaimed Emerging Threats Intelligence feed into Splunk, and provides predefined macros and lookups to enrich and search any log that Splunk can parse with ET Intelligence reputation data. The ET-TA installs in seconds, and empowers the Splunk admin to create custom searches, dashboards, panels, pivots, reports, and alerts enriched with ET intelligence data. Features: • Automatically Downloads, Installs, and Updates ET Intelligence reputation data. • Predefined Macros and Lookups to enrich any log containing IP/Domain fields that Splunk can parse with ET reputation data. • Support for Splunk Search, Dashboard, Panels, Pivots, Reports, and Alerts leveraging ET reputation data. • Splunk Adaptive Response Framework Support to automatically enrich IOCs with additional ET Intelligence data • Splunk Cloud Support
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources