Create and manage safelist libraries in Splunk Enterprise Security
Create safelists in Splunk Enterprise Security to exclude particular indicators from your threat lists generated by the threat intelligence management (cloud) system. Safelists ensure that threat lists remove indicators containing specific terms or phrases.
Follow these steps to add a safelist library:
- In Splunk Enterprise Security, select Configure and then Intelligence.
- In the Threat intelligence management (cloud) section, select Safelist libraries.
- Select + Add safelist library.
- Enter a name for the safelist.
- Enter each item one by one, or select Add safelist items in bulk to enter a full list of safelist items.
- Select Save.
After you add safelist libraries, you can edit or delete them from the list of libraries by selecting the pencil icon or the trash can icon.
See also
For more information on threat intelligence management (cloud), see the product documentation:
Use the inputintelligence command to use generic intelligence in Splunk Enterprise Security | Turn on threat matching searches in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 8.0.0, 8.0.1
Feedback submitted, thanks!