XTM Hub by FiligranSign In

[SIEM] Splunk Feed

A picture of U2hhcmVhYmxlUmVzb3VyY2VJbWFnZToxZDAwNjE5Zi03NGJlLTRmZjUtYWJhYy1jZjU3YTNmYzM1ODc=
A picture of U2hhcmVhYmxlUmVzb3VyY2VJbWFnZTowMGVlZDc1ZS0zMjBmLTRmZWMtODlhMC1mOTUyZmIwZjQ0OWQ=

Overview

This dashboard shows a similar widget field and layout to the widgets in the OpenCTI Splunk Add-on as published in Splunkbase

This dashboard has a layout very similar to the OCTI Splunk app, allowing the OpenCTI user to quickly check the nature of IOCs being sent to Splunk, as well as to compare counts on both Splunk and OpenCTI to verify the sync is operating correctly.

Note that this dashboard operates on the assumption that your Splunk Stream uses the same filter as the dashboard widgets! For the dashboard, this is Type = Indicator AND label = send_to_splunk. If you have a different filter on your Splunk stream, you should edit these

Basic Information

Filigran
Damian Skeeles
June 25, 2025
0
2