Enriching Data with Splunk Sightings

The Splunk Sightings enrichment renders matched raw events from your Splunk Cloud instance on observable details pages, accessible by drilling down on an observable in ThreatStream. The enrichment communicates directly with your Splunk Cloud instance on a per observable basis. Each time you open the Splunk Sightings tab in the Enrichments section of an observable details page, the enrichment initiates a full text search for the observable value in your Splunk events. If results are returned, raw events are displayed on the Splunk tab.

The enrichment times out if searches do not complete within 30 seconds.

Configuration involves pointing the enrichment to your Splunk Cloud instance and specifying the event set you want to search for matches.

Understanding Differences Between Splunk Sightings and My Attacks Report

This section outlines the differences between My Attacks Report and the Splunk Sightings Enrichment.

My Attacks Report:

  • Fetches select data fields from matched events on the Anomali ThreatStream Splunk App, such as attacker address and attack type.
  • Available for the Anomali ThreatStream Splunk App.

  • Does not fetch raw data.
  • Is generated on the Anomali ThreatStream Splunk App and routed to ThreatStream directly or through ThreatStream Integrator.
  • Populates the Sightings chart on observable details pages and the My Recent Attacks widget on the ThreatStream Overview Dashboard.

    See My Attacks Report for more information.

Splunk Sightings Enrichment:

  • Fetches matched events from Splunk Cloud instances.
  • Executes full text searches of Splunk events for observable values only when the Splunk tab is opened on an observable details page.
  • Fetches raw events rather than select fields.
  • Pulls data directly to ThreatStream from Splunk Cloud and populates the Splunk tab in the Enrichments section of observable details pages.
  • Available for any Splunk instance running in Splunk Cloud.

To activate Splunk Sightings:

  1. Navigate to ThreatStream > APP STORE > APP Store.

  2. Locate the Splunk Sightings enrichment.

  3. Click Get Access on the Splunk Sightings tile.

  4. On the wizard that opens, click I have credentials.
  5. On the next wizard page that opens, click Credentials and enter the following information:

    Field Description
    Host

    Domain name or IP address of your Splunk instance. Do not include protocols.

    The Splunk Sightings enrichment only supports the HTTPS protocol.
    Port

    Port used by your Splunk instance.

    Example: 8089

    User Name User name associated with your Splunk account.
    Password Password used to login to your Splunk account.
    Index

    Splunk index from which you want to retrieve sightings. The default value is used if not specified.

    Default: index=main

    Example: index=index1 OR index=index2

    Sourcetype

    Sourcetype for which you want to retrieve sightings. The default value is used if not specified.

    Default: sourcetype=*

    Example: sourcetype=fortinet OR sourcetype=websense

    Limit

    Number of results returned per observable. The default value is used if not specified.

    Default: 10

    Days back

    Amount of historical data in days you want to retrieve. The default value is used if not specified.

    Default: 1

    Example: 7

  6. Click Activate.

The Splunk Sightings enrichment is now active.