The main purpose of this Splunk App is the import of attributes/IOCs from MISP into a Splunk index. In order to use these IOCs for detection either as lookup or in Splunk Enterprise Security, the App provides some reports to generate IOC lookup-tables. These lookup-tables are compatible with the Threat Intelligence Framework of Splunk Enterprise Security.
(0)
Categories
Created By
Source Code
Type
Downloads
Licensing
Splunk Answers
Resources