Skip to content

Latest commit

 

History

History
30 lines (18 loc) · 1 KB

README.md

File metadata and controls

30 lines (18 loc) · 1 KB

ts_webhook_alert

Splunk alert action app for exporting indicators from Splunk to Anomali ThreatStream.

Installation

git clone https://github.com/vavarachen/ts_webhook_alert.git

tar -czf ts_webhook_alert.tar.gz ts_webhook_alert

Upload the tar.gz file to Splunk Search Head (Apps > Manage Apps > Install app from file)

Configuration

Find app ("Anomali Threatstream Indicator Export") and click "Set up" Setup

Example

Create a Splunk search which outputs indicators. Fields like 'tag', 'itype' are optional.

Splunk Search

Create an alert from the search.

Create Alert

Configure ts_webhook as 'Action'.

Configure Action