For reporting issues, please visit: https://github.com/lukemonahan/SA-otx
This app integrates OTX indicators collected by TA-otx into the Splunk Enterprise Security threat intelligence framework.
It does this within a modular input otx_intel_manager which periodically reads the data that has been collected by TA-otx and pushes it into the threat collections in a correctly structured manner.
Important: This add-on probably will not work well if your ES is deployed to a search head cluster, as the modular input will run at the same time on multiple search heads and cause race conditions. A future update will address search head clustering.
To set up this app after install:
1. Ensure that you have OTX data collected by TA-otx and it is fully backfilled to where you want it
1. Enable the otx_intel_manager://default modular input
The first backfill may take some time and can use CPU on your ES search head, depending upon how many OTX indicators you have indexed and are backfilling.
Currently evaluated indicator types from OTX are:
These map to threat intel groups and fields in Splunk ES according to the mapping that can be found in
bin/otx_intel_manager.py (search for the
Other field mappings that are important:
descriptionin the Splunk
threat_group_intelcollection is composed of both the pulse name and description from OTX
source_pathis the URL to view the pulse in detail in OTX
There are a set of disabled saved searches called
OTX <intel collection=""> - Retention included. When enabled, these will run overnight and remove any indicator older than 365 days. The exact length of retention can be tuned by modifying the
Splunk AppInspect evaluates Splunk apps against a set of Splunk-defined criteria to assess the validity and security of an app package and components.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 50GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps and add-ons from Splunk, our partners and our community. Find an app or add-on for most any data source and user need, or simply create your own with help from our developer portal.