Skip to main content
MISP Threat Fetcher app icon

MISP Threat Fetcher

Fetches threat intelligence data from MISP and seamlessly ingests it into Splunk for analysis, correlation, and threat detection.Built by Metron Consulting LLC, an official Splunk Partner
splunk product badge

Default Version 1.0.0

September 22, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.5, 10.4, 10.3, 10.2, 10.1, 10.0

Rating
0
(0)

Log in to rate this app

Support
Developer Supported

The MISP Splunk Add-on is a specialized integration tool that seamlessly ingests threat intelligence data from the Malware Information Sharing Platform (MISP) into Splunk. The add-on enables organisations to centralize and analyze Indicators of Compromise (IOCs), threat events, attributes, and other intelligence shared via MISP, providing security teams with enhanced visibility into evolving cyber threats. The add-on automates the entire threat intelligence ingestion process by securely connecting to the MISP REST API, retrieving new or updated threat data, and indexing it into Splunk. This eliminates the need for manual data exports and imports, ensuring that security analysts always have access to the latest threat intelligence within their Splunk environment. A key strength of the add-on is its ability to normalize MISP data into structured Splunk events, making threat indicators such as IP addresses, domains, URLs, file hashes, email addresses, malware samples, and event metadata easily searchable and available for correlation with existing security logs. This enables faster threat detection, investigation, and incident response. The add-on supports flexible configuration options, including customizable polling intervals, incremental data collection through checkpointing, secure API key authentication, SSL verification, and enterprise proxy support for deployments operating behind corporate firewalls. These capabilities make the add-on suitable for a wide range of enterprise environments. Compatible with Splunk Enterprise 10.0.0 and later, the MISP Splunk Add-on stores all collected threat intelligence in configurable Splunk indexes, allowing analysts to leverage Splunk's powerful search, dashboards, alerts, and correlation capabilities. By integrating external threat intelligence directly into Splunk, the add-on helps Security Operations Centers (SOCs) improve threat visibility, accelerate investigations, enrich detections, and strengthen their overall security posture through intelligence-driven security operations.