Version 1.1.0 introduces the SOCRadar TAXII 2.1 add-on for Splunk. This add-on collects threat intelligence data from SOCRadar's TAXII 2.1 server. Configure your TAXII credentials globally and set API root and collection IDs for each input. The add-on includes a dashboard to visualize collected threat indicators and supports incremental data collection with checkpoint tracking.
As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.