Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up

[SIEM] Splunk Feed

Detection & Response Enablement
A picture of RG9jdW1lbnQ6MDBlZWQ3NWUtMzIwZi00ZmVjLTg5YTAtZjk1MmZiMGY0NDlk
A picture of RG9jdW1lbnQ6MWQwMDYxOWYtNzRiZS00ZmY1LWFiYWMtY2Y1N2EzZmMzNTg3

Overview

This dashboard shows a similar widget field and layout to the widgets in the OpenCTI Splunk Add-on as published in Splunkbase

  • Note: The default timerange on this dashboard is "Last Month" - please reset this after loading.

This dashboard has a layout very similar to the OCTI Splunk app, allowing the OpenCTI user to quickly check the nature of IOCs being sent to Splunk, as well as to compare counts on both Splunk and OpenCTI to verify the sync is operating correctly.

Note that this dashboard operates on the assumption that your Splunk Stream uses the same filter as the dashboard widgets! For the dashboard, this is Type = Indicator AND label = send_to_splunk. If you have a different filter on your Splunk stream, you should edit these

Basic information

Filigran
Damian Skeeles
February 23, 2026
6.6.17
100+
40+

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".