Default Version 1.3.9
August 1, 2026
August 1, 2026
Splunk Enterprise, Splunk Cloud
Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0, 9.4, 9.3, 9.2, 9.1, 9.0
Log in to rate this app
The SOCRadar TAXII 2.1 Add-on enables Splunk users to collect threat intelligence feeds from SOCRadar's TAXII 2.1 server. It automates the ingestion of indicators such as malicious IPs, domains, URLs, and file hashes into Splunk for security monitoring and threat hunting. The add-on supports multiple collection feeds, incremental data updates, and includes a dashboard for threat visibility.
Log in to report this app listing.