Splunk threat intelligence
Splunk threat intelligence lets you correlate curated IOCs with your logs, so detections flag known-bad IPs, domains, URLs and hashes instead of leaving them buried.
- 2,500+Intelligence sources
- 20 minUpdate interval
- 5 minTo full integration
- 100%Made in Europe
What is the Q-Feeds and Splunk integration?
The Q-Feeds integration feeds curated cyber threat intelligence into Splunk so you can correlate our knowledge with the activity in your logs. Indicators of compromise are ingested into Splunk as lookups or into the Splunk Enterprise Security threat intelligence framework, ready for correlation searches.
This turns Splunk from a log store into an active detection engine: events that match known-malicious IPs, domains, URLs or hashes are surfaced automatically, so your SOC spots real threats faster and wastes less time on noise.
Q-Feeds combines commercial, OSINT and governmental intelligence, refreshed every 20 minutes and available over the open TAXII/STIX 2.1 standard for easy ingestion.
Correlate our knowledge with your logs
By adding threat intelligence to your SIEM you correlate our knowledge with the activity inside your infrastructure, giving you a convenient overview of every threat battering your organisation.
- A clear overview of the threats you face
- An enhanced overview so you can react faster
Feeds for every purpose
We offer a wide variety of feeds for different purposes (mobile threats, phishing, botnets, dark web and general malware), so you can focus on what matters most for your organisation.
- Tailored feeds for special purposes
- Always the latest intelligence, updated every 20 minutes
What we offer
Always ahead
Intelligence that updates every 20 minutes, so you are always ahead of the attackers.
Automatic response
Trust automated response actions and reduce the manual work needed to stop the latest threats.
Categories
Focus on what matters most, phishing, botnets, dark web and more crafted categories.
Knowledge
Knowledge is power when fighting threats. We take the knowledge part off your hands.
Easy implementation
You never did an implementation this easy. Follow our concise implementation guide and you are good to go.
Fewer false positives
We filter out false positives, so you never waste valuable resources chasing noise.
How to add threat intelligence to Splunk in 4 steps
Create your free account
Sign up on the Q-Feeds Threat Intelligence Portal and get your feed URLs and TAXII credentials.
Ingest the intelligence
Pull Q-Feeds IOCs into Splunk as lookups, or into the Splunk Enterprise Security threat intelligence framework over TAXII.
Correlate with your logs
Enable correlation searches that match your events against Q-Feeds indicators of compromise.
Alert and respond
Trigger notable events and automated response so your SOC acts on real threats faster.
Explore other SIEM integrations
Threat intelligence feeds
Curated IP, URL and domain feeds for your whole stack.
Microsoft Sentinel
One of the most used SIEMs, enriched with the right intelligence.
Other SIEMs
Many SIEM vendors support 3rd party threat intelligence.
Enrich my SIEM
Elevate the power of your SIEM solution by adding our intelligence.
Frequently asked questions about the Splunk integration
How does Q-Feeds work with Splunk?
Q-Feeds indicators of compromise are ingested into Splunk as lookups or into the Enterprise Security threat intelligence framework, where correlation searches match them against your log data.
Do I need Splunk Enterprise Security?
No. Q-Feeds works with the Splunk ES threat intelligence framework if you have it, but you can also correlate indicators using standard lookups and searches in core Splunk.
Which indicators can I correlate?
You can correlate malicious IP addresses, domains, URLs and file hashes across categories such as phishing, botnets, malware and dark web threats.
How is the intelligence delivered and updated?
Intelligence is available over the open TAXII/STIX 2.1 standard and as feeds, refreshed every 20 minutes so your correlations always use current data.
Is there a free version?
Yes. The free Community edition lets you test the Splunk integration before upgrading to Plus or Premium for faster, premium intelligence.
Evaluate our intelligence today!
Simplify your security operations, start your free Q-Feeds trial and experience the difference.
Activate free access