You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+55-72Lines changed: 55 additions & 72 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,4 +1,4 @@
1
-
# TA-opencti-for-splunk-enterprise
1
+
# OpenCTI for Splunk Enterprise (TA-opencti-for-splunk-enterprise)
2
2
3
3
**Version 1.0.0**
4
4
**Author:** Filigran
@@ -86,7 +86,11 @@ When configuring a modular input, you have two options for storing intelligence
86
86
- Write to a Splunk index, which will then propagate the data to a KV Store using saved searches
87
87
88
88
89
-
### KV Store Data Inputs configuration
89
+
### KV Store Ingestion Configuration
90
+
91
+
The KV Store data input type mode allows pre-defined KV Store to be directly fed with intelligence exposed by the OpenCTI live stream.
92
+
93
+

90
94
91
95
Proceed as follows to enable the ingestion of data in pre-defined KV Store:
92
96
@@ -129,53 +133,24 @@ You can also consult the "Monitoring Dashboard" which gives you an overview of i
129
133
130
134
The ingestion process can also be monitored by consulting the log file ```ta-opencti-for-splunk-enterprise_{DATA_INPUT_NAME}.log``` present in the directory ```$SPLUNK_HOME/var/log/splunk/```
131
135
132
-
### Index Data Inputs configuration
133
-
134
-
Proceed as follows to enable the ingestion of data in a Splunk index.
135
-
136
-
1. From the "OpenCTI for Splunk Enterprise Add-on" sub menus, select the "Inputs" sub menu.
## Index-Based Ingestion Configuration (Required for Saved Searches)
136
+
---
137
+
### Index-Based Ingestion Configuration (Required for Saved Searches)
164
138
165
139
When using **Index mode** ingestion, OpenCTI data is first written to a Splunk index and then synchronized into KV Store collections via saved searches.
140
+

141
+
166
142
This section explains **how to define the index**, **configure macros**, and **enable the required saved searches**.
167
143
168
-
---
169
144
170
-
## 1. Choose or Create a Splunk Index
145
+
####1. Choose or Create a Splunk Index
171
146
172
-
By default, the add-on **does not assume a fixed index name**.
147
+
By default, the add-on **does not assume a fixed Index name**.
173
148
174
-
### Recommended default index
149
+
####Recommended default index
175
150
```
176
151
opencti_data
177
152
```
178
-
### Create a dedicated index (recommended)
153
+
####Create a dedicated index (recommended)
179
154
180
155
In Splunk Web:
181
156
@@ -190,48 +165,56 @@ In Splunk Web:
190
165
191
166
---
192
167
193
-
## 2. Configure the OpenCTI Modular Input (Index Mode)
168
+
#### 2. Configure the OpenCTI Modular Input (Index Mode)
169
+
170
+
1. From the "OpenCTI for Splunk Enterprise Add-on" sub menus, select the "Inputs" sub menu.
0 commit comments