ThreatStream Integrator

Anomali ThreatStream Integrator (the next generation of ThreatStream Link) is the software for integrating your existing security infrastructure to Anomali's ThreatStreamCloud or ThreatStream OnPrem.

ThreatStream Integrator connects to the ThreatStream platform or the ThreatStream appliance and pulls rich cyber threat intelligence feeds into existing tools and infrastructure thus bringing real-time intelligence into your existing security solutions to provide operational efficiency and relevancy to current security technologies. It can output this data in many formats such as CSV, Syslog, and Common Event Format (CEF), and can also directly integrate with security solutions in your network, such as SIEMs, firewalls, end-point security solutions, DNS, and Hadoop-based systems.

Supported Integrations

In addition to the ability to configure custom destinations, ThreatStream Integrator enables integrations with the following services:

Product Class Product
SIEM ArcSight ESM, Splunk, QRadar, McAfee ESM (NitroSecurity), LogRhythm, AccelOps, RSA NetWitness, Bro_intel
Firewalls Palo Alto Networks, Blue Coat Proxy SG, Check Point, Cisco ASA
Endpoint Security Carbon Black, Tanium, CrowdStrike, FireEye HX
Hadoop Cloudera Impala, Hadoop Hive
DNS Infoblox

Anomali is always adding new integrations. If your product is not represented in the above list, contact sales@anomali.com to learn about our upcoming integrations.

Downloading ThreatStream Integrator

You can download ThreatStream Integrator from the Downloads page on ThreatStream. Also available on the Downloads page is the ThreatStream Integrator Installation & Administration Guide, which contains information on installing and using ThreatStream Integrator.

If you do not have access to the Downloads page from the ThreatStream UI, contact your Anomali Sales representative.