Configure Anomali Threatstream client to collect Indicator data from the Splunk Intelligence Management
Configure the Anomali Threatstream TAXII client to collect Indicator data from the Splunk Intelligence Management TAXII server and make that data available for analysis in Anomali Threatstream.
Prerequisites
- Download and install Anomali Threatstream.
- Access your Splunk Intelligence Management API key and API secret. For more information on finding your API key, see Find your API key.
Configure the Anomali Threatstream TAXII client
- Navigate to Settings > TAXII.
- Click the TAXII Feeds tab.
- Click Actions and select New TAXII Feed.
- Select the following options for the new feed:
- Name for the TAXII Feed.
- Expiration date. Use the default value of 90 days.
- Whether to override the system confidence or not.
If you check this option, set the confidence level. Use the default setting, which is unchecked.
- Navigate to Settings > TAXII.
- Click the Sites tab.
- Click Actions and select Add Site.
- Edit the following fields in the New Site dialog box:
- Descriptive Name: Enter a the feed name. Include "Splunk Intelligence Management" in the name so that you can remember the feed source.
- Discovery URL: Enter the discovery URL.
- Authentication: Select Basic Authentication.
- Username: Enter your Splunk Intelligence Management API key.
- Password: Enter your Splunk Intelligence Management API secret.
- Click Add Site to create the new site. The new site appears on the Sites tab.
- Select the checkbox next to the site that you just created and click on [...] to configure it. The settings for that site are displayed.
- Confirm that DISCOVERY OK is selected in the Discovery box.
- Click Configure under the collection name to access the Feed Configuration dialog.
- Enter the following information in the Feed Configuration dialog:
- Leave Subscription ID empty.
- Select an Interval for how often to poll.
- Select the Date and Time you want the poll to start.
- Click Save and Run Now to complete the configuration.
Troubleshooting
If you do not see the Poll Collections tab after configuration, check the Threatstream User Administrator or the Users page to verify that the the user is granted the Import to TAXII Feeds permission.
This documentation applies to the following versions of Splunk® Intelligence Management (Legacy): current
Feedback submitted, thanks!