Integrating with Splunk Cloud
If your organization subscribes to the Splunk Cloud service, you can use this integration to send intelligence from ThreatStream to the Splunk Cloud. ThreatStream generates intelligence snapshots based on a filter you specify. Before generating intelligence snapshots, ThreatStream removes observables that match entries on your organization Exclude List from the snapshot.
To integrate ThreatStream with Splunk Cloud:
-
In the bottom-left corner of the side navigation panel, click
> ThreatStream and then click Integrations. - Click Activate in the Splunk Cloud box.
- Enter a Search Filter. This determines which observables are included in snapshot downloads. For a list of valid fields and operators, see Search Operators.
- Click Save.