XTM Hub by Filigran

OpenCTI Add-on for Splunk

Detection & Response Enablement
A picture of RG9jdW1lbnQ6MDZkZWYyNWUtZGExZS00MDJiLTk2ZGItODNmNjhhMmYxMmI5

Aperçu

The OpenCTI Add-on for Splunk enables real-time indicator ingestion through live streams and allows analysts to trigger OpenCTI actions directly from Splunk alerts.

The OpenCTI Add-on for Splunk allows users to interconnect their Splunk environment with the OpenCTI platform. This integration enables security teams to enhance their detection and response workflows by leveraging OpenCTI's threat intelligence directly within Splunk.

Key capabilities include:

  • Live Stream Indicator Ingestion: Ingest indicators exposed through OpenCTI live streams in real-time, ensuring your Splunk environment continuously receives the latest threat intelligence
  • Alert-based Actions: Trigger OpenCTI actions in response to Splunk alerts, enabling automated threat intelligence operations based on security events detected in your SIEM
  • Direct Investigation in OpenCTI: Investigate alerts directly in the OpenCTI platform from Splunk, providing analysts with immediate access to enriched threat context and collaborative investigation capabilities

Informations de base

Filigran
Nino Rowlands
Intégrations tierces (bientôt disponible)
Endpoint Detection & Response
19 août 2026
6.2.0
2

    Nous utilisons des cookies pour assurer le fonctionnement de XTM Hub. Les cookies nécessaires sont toujours activés ; les cookies facultatifs (fonctionnels, d'analyse, de marketing) ne sont utilisés qu'avec votre consentement. Vous pouvez accepter tous les cookies, les refuser tous ou gérer vos préférences à tout moment dans la rubrique « Paramètres des cookies ».