The iDefense Intelgraph Add-On allows you to:
Installation and Configuration documents can be found here.
Note:
- Patch version 7.3.5 is required for this TA to Work with Splunk Version 7.3
New content:
3.1
- Added file indicators collection and threat intelligence
- Updated the threat match correlation search for file indicator match
- Branding changed from iDefense to ACTI
3.0
- ACTI Integration Health Check Dashboard.
- Correlation Search that triggers notables for ACTI Threat Match.
- ACTI KV stores to store added ACTI context for indicators.
- Macros for enriching data with ACTI Context
- Updated threat indicator Download Commands.
- Added support for ACTI Plugin for Splunk Mission Control.
Note:
- Patch version 7.3.5 is required for this TA to Work with Splunk Version 7.3
Following New Contents were added:
- ACTI Integration Health Check Dashboard.
- Correlation Search that triggers notables for ACTI Threat Match.
- ACTI KV stores to store added ACTI context for indicators.
- Macros for enriching data with ACTI Context
Updates:
- Updated threat indicator Download Commands.
- Added support for ACTI Plugin for Splunk Mission Control.
This version updates our supported versions of Splunk through 8.1. No other features or fixes are included; however, we are actively developing improvements and will share more information soon.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.