> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pulsedive.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Integrate with Splunk Enterprise Security

> Bring Pulsedive threat intelligence into Splunk Enterprise Security as a CSV-based lookup for correlation and risk scoring.

Splunk Enterprise Security is a SIEM application that security teams use to detect, investigate, and respond to threats across their environment.
Its threat intelligence framework correlates indicators from external sources against your event data and factors them into risk scoring.
With this integration, Splunk Enterprise Security ingests Pulsedive's scored, de-duplicated indicators so you can match them against your logs.

<Note>
  Splunk Enterprise Security's STIX parser reads STIX `observed-data` objects, but doesn't support the pattern syntax used inside STIX `indicator` objects.
  Pulsedive's TAXII server transmits `indicator` objects, so this integration uses Pulsedive's CSV export instead.
</Note>

## Prerequisites

Before you connect Splunk Enterprise Security to Pulsedive, make sure you have Splunk Enterprise Security with permission to add and manage threat intelligence sources.

You will also need the following from Pulsedive:

* A Pulsedive account and API key.
  Find your API key on your [Pulsedive account page](https://pulsedive.com/account).
* A Pulsedive Feed plan that includes CSV export.

## Exporting Your Indicators from Pulsedive

Generate the CSV file that you will upload to Splunk Enterprise Security as a lookup.

<Steps>
  <Step title="Build your Direct URL">
    Construct your Direct URL using available parameters in [CSV Export](https://docs.pulsedive.com/export/csv).
    The URL includes your API key, so keep it private.
  </Step>

  <Step title="Download the CSV file">
    Go to your Direct URL in a browser to save the file locally.
  </Step>
</Steps>

<Note>
  Splunk Enterprise Security doesn't poll this URL on a schedule the way it does with a remote TAXII or CSV data source.
  To keep your indicators current, repeat this export periodically; see [Keeping your lookup up to date](#keeping-your-lookup-up-to-date).
</Note>

## Adding Pulsedive as a Lookup in Splunk Enterprise Security

Add the CSV file as a managed lookup, then create a threat intelligence source that points to it, so Splunk Enterprise Security parses the file into its threat intelligence collections.

<Steps>
  <Step title="Add the lookup file">
    1. In Splunk Enterprise Security, use the navigation menu to go to **Security content** > **Content management**.
    2. Select **Create New Content** > **Managed Lookup**, then **Create New**.
    3. Select the Pulsedive CSV file you downloaded.
    4. Enter details for the lookup:
       | Field Name | Description |
       | - | - |
       | **App** | App context for the lookup; set to `SA-ThreatIntelligence` |
       | **Definition name** | Internal name you will reference when you create the threat intelligence source in the next step (for example, `pulsedive_indicators_list`) |
       | **Lookup type** | Leave as the default, `Manual editing` |
       | **Label** | Human-readable name that identifies the lookup (for example, `Pulsedive Indicators`) |
       | **Description** | Description of the lookup (for example, `Pulsedive threat intelligence lookup`) |
    5. Select **Save**.
  </Step>

  <Step title="Map Pulsedive's fields to a threat intelligence source">
    Pulsedive's CSV columns use Pulsedive's own field names (`ioc`, `type`, `risk`, `threats`, `feeds`, `riskfactors`, `usersubmissions`) rather than the field names Splunk's built-in collections expect (for example, `ip` or `domain`).
    Map them when you create the source:

    1. Use the navigation menu to go to **Configure** > **Threat intelligence**.
    2. On the **Data sources** page, select **+ Data Source**.
    3. Enter details for the source:
       | Field Name | Description |
       | - | - |
       | **Name** | Identifier for the source, with no spaces (for example, `pulsedive_indicators`) |
       | **Type** | Category label for the intelligence (for example, `pulsedive_ioc`) |
       | **Description** | Description of the source (for example, `Pulsedive threat intelligence`) |
       | **URL** | `lookup://` followed by the lookup definition name you created in the previous step (for example, `lookup://pulsedive_indicators_list`) |
       | **Fields** | Mapping of each Pulsedive column to the field name your target collection expects (for example, `ioc` to `ip` for the `ip_intel` collection). To explore the field names each collection expects, visit Splunk's [supported types of threat intelligence](https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.5/threat-intelligence/supported-types-of-threat-intelligence-in-splunk-enterprise-security) reference. |
    4. Select **Save**.
  </Step>
</Steps>

## Verifying the Connection

Confirm that Pulsedive indicators parsed successfully before you rely on them.
Splunk Enterprise Security's modular input parses lookup-based sources on a periodic schedule (every 12 hours by default), so allow time after your first upload before checking.

1. Go to **Analytics** > **Security Intelligence** > **Threat Intelligence** > **Threat Findings**.
2. In the **Intel Source ID** field, search for the **Name** you gave the source in the previous section.
3. Confirm that indicators appear for the source.

If indicators don't appear, review the Intelligence Audit Events panel on the **Threat Intelligence Audit** dashboard or check the `threat_intelligence_manager.log` file for parsing errors.

## Using Pulsedive Data in Splunk Enterprise Security

Once Pulsedive indicators are in your threat intelligence collections, Splunk Enterprise Security correlates them against your data and factors them into risk scoring.
Its threat-matching searches compare incoming events against the Pulsedive indicators and raise notable events when they match, so the data flows into your existing triage and investigation workflows.

## Keeping Your Lookup Up to Date

Splunk Enterprise Security doesn't refresh a lookup-based source from Pulsedive, so replace the lookup file whenever you want current indicators.

### Automating the Refresh

If you have file system access to a standalone Splunk search head, schedule a job that downloads your Direct URL and overwrites the lookup file.
Splunk stores the managed lookup at `$SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/lookups/`, under the file name you uploaded.

Follow these practices when you set up the job:

* Use the same Direct URL you exported with, so the columns still match your field mapping.
* Run the job at most once every 8 hours.
* Store your Direct URL as a secret, because it contains your API key.

Splunk doesn't replicate files that you change directly on disk across a search head cluster, so update a clustered deployment manually.

To learn more about scheduling exports, visit [Automate Your Export](/export/automate).

### Updating the Lookup Manually

If you can't write to the search head's file system, replace the file in Splunk Enterprise Security:

1. Repeat the export from [Exporting your indicators from Pulsedive](#exporting-your-indicators-from-pulsedive).
2. Use the navigation menu to go to **Security content** > **Content management**.
3. Select the lookup you created.
4. Upload the new file.

Splunk Enterprise Security picks up the change the next time its modular input parses the source.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.