icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading IPURL IOC Ingestion
SHA256 checksum (ipurl-ioc-ingestion_106.tgz) 06cea6beb02e637dba5dbb35e1451f0a14c2c1f85f6046ba822166e0fac66f69 SHA256 checksum (ipurl-ioc-ingestion_104.tgz) 95877e38d9844b6bc6f70267a625287506eabfe665df8ba18167f0289fe103e1 SHA256 checksum (ipurl-ioc-ingestion_102.tgz) 85cf5c628c1be8434acb72da95a898792b6d304aeb15a340e65d9021c7793c7f SHA256 checksum (ipurl-ioc-ingestion_100.tgz) 9081a2de3ad5587ef1004738060e49eaebc1322f47f6df2c9c9a9b33afd48d84
To install your download
For instructions specific to your download, click the Details tab after closing this window.

Flag As Inappropriate

splunk

IPURL IOC Ingestion

Overview
Details
Note: This Add-on does not work on a Cluster Environment. It only works on Splunk Enterprise and a single instance of Splunk Cloud.
Am working to fix the issue related to it not working on a Cluster environment.

This Add-on collects IPs, URLs and Domains from well known Open-source websites that can be used by Threat Intelligence analysts or Cyber Security Centres for better correlations of their use cases or searches. It is needed by any security team that do not use MISP and need to retrieve open source IPs, URLs and Domains.

The Add-on downloads IPs, Domains, URLs and Phishing Domains from Proof Point IP blocklist, Abuse CNC blocklist, URLHAUS, OpenPhish, DigitalSide Threat-Intel repo FQDN domains, Mitchell Krogza Github phishing domain lists and Romain Marcoux Github phishing domain lists..
All these lists are cleaned and placed into a CSV file that can be used for correlation after the user has created a new input after the installation.

NOTE: This add-on works properly only on a Single Instance of Splunk Cloud and Splunk Enterprise. It does not work on a Cluster environment.
Am working to fix this issue.

This Add-on does not add any logs to Splunk license because it does not ingest the logs into any index.

The logs are filtered by it and properly formatted into csv files that are named on the add-on.
It is built for security teams that do not have MISP installed but need to ingest IOCs that can be used for use case correlation or for threat hunting. It does not have all the IPs, and URLs but it has some that can help any security team from reputable open source websites such as Abuse.ch and Proofpoint firewall block IPs

Release Notes

Version 1.0.6
Oct. 13, 2024
  • Added more IOCs sources from reputable sites such as OpenPhish urls, DigitalSide Threat-Intel repo FQDN domains, Mitchell Krogza Github phishing domain lists and Romain Marcoux Github phishing domain lists.
  • Removed the default clicked action. Users will need to check the button to start collecting IOCs when creating the input.
Version 1.0.4
Oct. 6, 2024
  • Removed Cisco Talos IP Blocklist since it is a little bit difficult to download using the basic python script
  • Made the add-on compliant with Splunk Cloud 9.
Version 1.0.2
Aug. 26, 2023

New feature for version 1.0.2

  • Added a search named ioc-opensourceIP that combines all the IPs into one CSV file and removes duplicate IPs from the lists. This search runs once daily and replaces the old csv file with a new one every time it runs.

  • In order for the search which is located on the IPURL IOC Ingestion app to run, it needs to be enabled.

Note: When it runs the first time, it produces this error "The lookup table 'ioc-opensourceIP.csv' requires a .csv or KV store lookup definition".
That is what happens in Splunk when the outputlookup command is used in a search and needs to create a new file that was not previously created. Refresh to see the results and since the new csv file is created. It should run smoothly.

Version 1.0.0
Aug. 12, 2023

This Addon downloads IPs and URL from Proofpoint IP blocklist, Cisco Talos Snort blocklist, Abuse CNC blocklist and URLHAUS. All these lists are cleaned and placed into a CSV file that can be used for correlation.
A search will be needed by the security team to combine these IPs into one CSV file to remove duplicates from all these sources on version 1.0.0.

Note: In order for the Add-on to start downloading new IOCs, a new input will need to be created after the installation.

As regarding Splunk Cloud, this Add-on should be installed on Splunk Cloud IDM but the new input should be created on the Splunk Cloud Search Head in order for the CSV files to be properly used in the correlation.
As regarding Splunk Enterprise, this add-on can be installed on either the Indexer or Search head depending on where the correlation needs to be done.


Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.