Skip to main content
Warning
This app is archived. App archiving documentation
Qintel QSentry Feed Add-on for Splunk app icon

Qintel QSentry Feed Add-on for Splunk

QSentry is a consumable feed of anonymization and threat actor IP addresses sourced from the Deep and DarkWeb and QIntel’s proprietary research. The IPs in the feed are associated with infrastructure actively utilized or abused by cyber criminals, including VPN/Proxy services and IP addresses linked to the malicious infrastructure of criminal and nation-state actors. With this integration, users can fetch a daily list of newly compiled indicators from QSentry’s collections.Built by Qintel Integrations
splunk product badge

Default Version 1.1.0

May 3, 2024

Compatibility

Splunk Enterprise

Platform Version: 9.4, 9.3, 9.2, 9.1, 9.0

CIM Version: 5.x, 4.x, 3.x

Rating
0
(0)

Log in to rate this app

Support
Archived Add-on

QSentry is a consumable feed of anonymization and threat actor IP addresses sourced from the Deep and DarkWeb and QIntel’s proprietary research. The IPs in the feed are associated with infrastructure actively utilized or abused by cyber criminals, including VPN/Proxy services and IP addresses linked to the malicious infrastructure of criminal and nation-state actors. With this integration, users can fetch a daily list of newly compiled indicators from QSentry’s collections. The Qintel QSentry Technology Add-on allows you to ingest the Qintel QSentry feed into a key value store in Splunk so that your logs data can be enriched automatically or at search time.