ThreatStream Integrator
Anomali ThreatStream Integrator (the next generation of ThreatStream Link) is the software for integrating your existing security infrastructure to Anomali's ThreatStreamCloud or ThreatStream OnPrem.
ThreatStream Integrator connects to the ThreatStream platform or the ThreatStream appliance and pulls rich cyber threat intelligence feeds into existing tools and infrastructure thus bringing real-time intelligence into your existing security solutions to provide operational efficiency and relevancy to current security technologies. It can output this data in many formats such as CSV, Syslog, and Common Event Format (CEF), and can also directly integrate with security solutions in your network, such as SIEMs, firewalls, end-point security solutions, DNS, and Hadoop-based systems.
Supported Integrations
In addition to the ability to configure custom destinations, ThreatStream Integrator enables integrations with the following services:
| Product Class | Product |
|---|---|
| SIEM | ArcSight ESM, Splunk, QRadar, McAfee ESM (NitroSecurity), LogRhythm, AccelOps, RSA NetWitness, Bro_intel |
| Firewalls | Palo Alto Networks, Blue Coat Proxy SG, Check Point, Cisco ASA |
| Endpoint Security | Carbon Black, Tanium, CrowdStrike, FireEye HX |
| Hadoop | Cloudera Impala, Hadoop Hive |
| DNS | Infoblox |
Anomali is always adding new integrations. If your product is not represented in the above list, contact sales@anomali.com to learn about our upcoming integrations.
Downloading ThreatStream Integrator
You can download ThreatStream Integrator from the Downloads page on ThreatStream. Also available on the Downloads page is the ThreatStream Integrator Installation & Administration Guide, which contains information on installing and using ThreatStream Integrator.