Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Integration of MISP with Splunk Cloud #169

Closed
narendrahm opened this issue Oct 5, 2020 · 6 comments
Closed

Integration of MISP with Splunk Cloud #169

narendrahm opened this issue Oct 5, 2020 · 6 comments

Comments

@narendrahm
Copy link

Is there any way to integrate MISP with Splunk Cloud

@gregzee
Copy link

gregzee commented Oct 19, 2020

I see that a few versions are compatible for Splunk Cloud, but there isn't any documentation on this particular integration.

@remg427
Copy link
Owner

remg427 commented Oct 20, 2020

Hi,
misp42splunk is designed to be on a SH: it has custom commands and 2 alert actions. no data is ingested via forwarder
I am working on a cleaner version with a lookup to manage MISP instances.

@gregzee
Copy link

gregzee commented Oct 21, 2020

@remg427

I was under the impression we can pull IOC/Threat Intel from MISP into Splunk/Splunk Cloud. If it is still on the SH, is it still possible?

I am assuming with the custom commands we can pull from MISP, but would like to verify. Thank you for the reply.

Thanks!

@remg427
Copy link
Owner

remg427 commented Nov 9, 2020

version 4 should pass cloud vetting process.
to pull data from MISP you can use custom commands and alert actions to push data
in version4 there is also a wrapper for MISP API misprest. provided you build a valid JSON request.

@remg427
Copy link
Owner

remg427 commented Nov 23, 2020

version 4.0.0 has been vetted for deployment on Splunk Cloud
Products: Splunk Enterprise, Splunk Cloud
Splunk Versions: 8.1, 8.0

@remg427 remg427 closed this as completed Nov 23, 2020
@narendrahm
Copy link
Author

narendrahm commented Nov 23, 2020 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants