The Security Threat Intelligence Add-On for Splunk enhances an organization's ability to detect, investigate, and respond to cyber threats in real time. By integrating multiple external threat intelligence sources, the add-on normalizes and enriches incoming data for compatibility with Splunk’s Common Information Model (CIM). It delivers actionable insights through dashboards, alerts, and automated email alerts. This enables security teams to efficiently prioritize threats, streamline incident response, and strengthen their overall security posture. The OSINT sources used are AbuseIP DB, AlienVaultOTX and Abuse.ch.
My Final Year Project. A Security Threat Intelligence Add-On for Splunk which is designed to enhance the security monitoring capabilities of Splunk users. This is done by integrating external threat intelligence feeds directly into their environment. This add-on helps users to stay updated with the latest security threats, automate data ingestion, and correlate that threat intelligence with internal data for faster detection and response. It enables enhanced security analytics and improved incident response through real-time threat intelligence.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.