Splunk Enterprise Security’s STIX parser reads STIX
observed-data objects, but doesn’t support the pattern syntax used inside STIX indicator objects.
Pulsedive’s TAXII server transmits indicator objects, so this integration uses Pulsedive’s CSV export instead.Prerequisites
Before you connect Splunk Enterprise Security to Pulsedive, make sure you have Splunk Enterprise Security with permission to add and manage threat intelligence sources. You will also need the following from Pulsedive:- A Pulsedive account and API key. Find your API key on your Pulsedive account page.
- A Pulsedive Feed plan that includes CSV export.
Exporting Your Indicators from Pulsedive
Generate the CSV file that you will upload to Splunk Enterprise Security as a lookup.1
Build your Direct URL
Construct your Direct URL using available parameters in CSV Export.
The URL includes your API key, so keep it private.
2
Download the CSV file
Go to your Direct URL in a browser to save the file locally.
Splunk Enterprise Security doesn’t poll this URL on a schedule the way it does with a remote TAXII or CSV data source.
To keep your indicators current, repeat this export periodically; see Keeping your lookup up to date.
Adding Pulsedive as a Lookup in Splunk Enterprise Security
Add the CSV file as a managed lookup, then create a threat intelligence source that points to it, so Splunk Enterprise Security parses the file into its threat intelligence collections.1
Add the lookup file
- In Splunk Enterprise Security, use the navigation menu to go to Security content > Content management.
- Select Create New Content > Managed Lookup, then Create New.
- Select the Pulsedive CSV file you downloaded.
- Enter details for the lookup:
- Select Save.
2
Map Pulsedive's fields to a threat intelligence source
Pulsedive’s CSV columns use Pulsedive’s own field names (
ioc, type, risk, threats, feeds, riskfactors, usersubmissions) rather than the field names Splunk’s built-in collections expect (for example, ip or domain).
Map them when you create the source:- Use the navigation menu to go to Configure > Threat intelligence.
- On the Data sources page, select + Data Source.
- Enter details for the source:
- Select Save.
Verifying the Connection
Confirm that Pulsedive indicators parsed successfully before you rely on them. Splunk Enterprise Security’s modular input parses lookup-based sources on a periodic schedule (every 12 hours by default), so allow time after your first upload before checking.- Go to Analytics > Security Intelligence > Threat Intelligence > Threat Findings.
- In the Intel Source ID field, search for the Name you gave the source in the previous section.
- Confirm that indicators appear for the source.
threat_intelligence_manager.log file for parsing errors.
Using Pulsedive Data in Splunk Enterprise Security
Once Pulsedive indicators are in your threat intelligence collections, Splunk Enterprise Security correlates them against your data and factors them into risk scoring. Its threat-matching searches compare incoming events against the Pulsedive indicators and raise notable events when they match, so the data flows into your existing triage and investigation workflows.Keeping Your Lookup Up to Date
Splunk Enterprise Security doesn’t refresh a lookup-based source from Pulsedive, so replace the lookup file whenever you want current indicators.Automating the Refresh
If you have file system access to a standalone Splunk search head, schedule a job that downloads your Direct URL and overwrites the lookup file. Splunk stores the managed lookup at$SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/lookups/, under the file name you uploaded.
Follow these practices when you set up the job:
- Use the same Direct URL you exported with, so the columns still match your field mapping.
- Run the job at most once every 8 hours.
- Store your Direct URL as a secret, because it contains your API key.
Updating the Lookup Manually
If you can’t write to the search head’s file system, replace the file in Splunk Enterprise Security:- Repeat the export from Exporting your indicators from Pulsedive.
- Use the navigation menu to go to Security content > Content management.
- Select the lookup you created.
- Upload the new file.