Splunk

Splunk threat intelligence

Splunk threat intelligence lets you correlate curated IOCs with your logs, so detections flag known-bad IPs, domains, URLs and hashes instead of leaving them buried.

  • 2,500+Intelligence sources
  • 20 minUpdate interval
  • 5 minTo full integration
  • 100%Made in Europe
What it is

What is the Q-Feeds and Splunk integration?

The Q-Feeds integration feeds curated cyber threat intelligence into Splunk so you can correlate our knowledge with the activity in your logs. Indicators of compromise are ingested into Splunk as lookups or into the Splunk Enterprise Security threat intelligence framework, ready for correlation searches.

This turns Splunk from a log store into an active detection engine: events that match known-malicious IPs, domains, URLs or hashes are surfaced automatically, so your SOC spots real threats faster and wastes less time on noise.

Q-Feeds combines commercial, OSINT and governmental intelligence, refreshed every 20 minutes and available over the open TAXII/STIX 2.1 standard for easy ingestion.

SIEM enrichment

Correlate our knowledge with your logs

By adding threat intelligence to your SIEM you correlate our knowledge with the activity inside your infrastructure, giving you a convenient overview of every threat battering your organisation.

  • A clear overview of the threats you face
  • An enhanced overview so you can react faster
Threat intelligence feeds

Feeds for every purpose

We offer a wide variety of feeds for different purposes (mobile threats, phishing, botnets, dark web and general malware), so you can focus on what matters most for your organisation.

  • Tailored feeds for special purposes
  • Always the latest intelligence, updated every 20 minutes
Features

What we offer

Always ahead

Intelligence that updates every 20 minutes, so you are always ahead of the attackers.

Automatic response

Trust automated response actions and reduce the manual work needed to stop the latest threats.

Categories

Focus on what matters most, phishing, botnets, dark web and more crafted categories.

Knowledge

Knowledge is power when fighting threats. We take the knowledge part off your hands.

Easy implementation

You never did an implementation this easy. Follow our concise implementation guide and you are good to go.

Fewer false positives

We filter out false positives, so you never waste valuable resources chasing noise.

How it works

How to add threat intelligence to Splunk in 4 steps

  1. Create your free account

    Sign up on the Q-Feeds Threat Intelligence Portal and get your feed URLs and TAXII credentials.

  2. Ingest the intelligence

    Pull Q-Feeds IOCs into Splunk as lookups, or into the Splunk Enterprise Security threat intelligence framework over TAXII.

  3. Correlate with your logs

    Enable correlation searches that match your events against Q-Feeds indicators of compromise.

  4. Alert and respond

    Trigger notable events and automated response so your SOC acts on real threats faster.

FAQ

Frequently asked questions about the Splunk integration

How does Q-Feeds work with Splunk?

Q-Feeds indicators of compromise are ingested into Splunk as lookups or into the Enterprise Security threat intelligence framework, where correlation searches match them against your log data.

Do I need Splunk Enterprise Security?

No. Q-Feeds works with the Splunk ES threat intelligence framework if you have it, but you can also correlate indicators using standard lookups and searches in core Splunk.

Which indicators can I correlate?

You can correlate malicious IP addresses, domains, URLs and file hashes across categories such as phishing, botnets, malware and dark web threats.

How is the intelligence delivered and updated?

Intelligence is available over the open TAXII/STIX 2.1 standard and as feeds, refreshed every 20 minutes so your correlations always use current data.

Is there a free version?

Yes. The free Community edition lets you test the Splunk integration before upgrading to Plus or Premium for faster, premium intelligence.

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access