OpenCTI または OpenAEV プラットフォームを 30 日間お試しいただけます。 無料トライアル
XTMハブ by フィリグラン
サインアップ

OpenCTI Add-on for Splunk

Detection & Response Enablement
A picture of RG9jdW1lbnQ6MDZkZWYyNWUtZGExZS00MDJiLTk2ZGItODNmNjhhMmYxMmI5

概要

The OpenCTI Add-on for Splunk enables real-time indicator ingestion through live streams and allows analysts to trigger OpenCTI actions directly from Splunk alerts.

The OpenCTI Add-on for Splunk allows users to interconnect their Splunk environment with the OpenCTI platform. This integration enables security teams to enhance their detection and response workflows by leveraging OpenCTI's threat intelligence directly within Splunk.

Key capabilities include:

  • Live Stream Indicator Ingestion: Ingest indicators exposed through OpenCTI live streams in real-time, ensuring your Splunk environment continuously receives the latest threat intelligence
  • Alert-based Actions: Trigger OpenCTI actions in response to Splunk alerts, enabling automated threat intelligence operations based on security events detected in your SIEM
  • Direct Investigation in OpenCTI: Investigate alerts directly in the OpenCTI platform from Splunk, providing analysts with immediate access to enriched threat context and collaborative investigation capabilities

基本情報

Filigran
Nino Rowlands
サードパーティとの統合
Endpoint Detection & Response
2026年8月19日
6.2.0
0

    XTM Hubの運営にはクッキーを使用しています。必須のクッキーは常に有効になっていますが、オプションのクッキー(機能、分析、マーケティング)は、お客様の同意を得た上で使用されます。「クッキー設定」から、いつでも「すべて受け入れる」、「すべて拒否する」、または設定を管理することができます。