ticura logoticura logo

Splunk Enterprise Security - Setup & config guide

Overview

Splunk Enterprise Security supports the consumption of Threat Intelligence Feeds provided by Ticura via Threat Intelligence Management since version 8.2.

Prepare Ticura subscriptions based on your requirements

To create a subscription, follow the steps described in the getting started guide (login required)

  • Select output formats Stix / Taxii 2.1
  • Select authentication method(s) basicAuth

Creating the subscription results in credentials and example curl code that contains the URL ( different for each output format ) to access the feed:

SettingValue
Taxii Base URLhttps://taxii.ticura.io
Discovery Endpointhttps://taxii.ticura.io/taxii2/
API Roothttps://taxii.ticura.io/B76B1571-XXXX-XXXX-XXXX-83557F86C91F/
CollectionIDB76B1571-XXXX-XXXX-XXXX-83557F86C91F
Usernamegenerated-username
Passwordgenerated-password

Configure your Splunk Enterprise Security to consume the Ticura Threat Intelligence Feed

Add a new Threat Intelligence "Source" at Splunk Enterprise Security

Reference Documentation

  1. Login into "Splunk Enterprise" and open the "Splunk Enterprise Security" APP
  2. navigate to "Configure" -> "General Settings" -> "Credentials"

  3. Click "New Credential" -> configure your ticura Feed Username / Password -> Save

  4. navigate to "Configure" -> "Threat Intelligence" and Click "New" - "TAXII2"

  5. Configure the new source with data from created subscription and save it
  • General Tab
SettingValue
Namemy-ticura-feed-name
Descriptionmy feed description
Urlhttps://taxii.ticura.io/B76B1571-XXXX-XXXX-XXXX-83557F86C91F/collections/B76B1571-XXXX-XXXX-XXXX-83557F86C91F
Weight60
Interval (s)900
Max Age-30d
Max Size5242880099
Threat Intelligencetrue

  • Advanced Tab
    • Remote Site User: generated-username

Check successful data import

  1. Login into Splunk Enterprise and open the Splunk Enterprise Security APP
  2. navigate to "Audit" -> "Threat Intelligence Audit"
  3. check exit status of configured source / stanza. It must be 0

  4. navigate to "Analytics" -> "Security Intelligence" -> "Threat Intelligence" -> "Indicators" and ensure that artefacts have been imported

IOC Expiration / deletion

Official documentation mentions that Splunk Enterprise Security ignores the "Max Age:" Settings on TAXII2 Threat Intelligence Sources.

Imported Data will be stored until Default KV Store cleanup jumps in. Default Retention Time for EES KV Stores is 60 days. Configuration possible based on following Doku: Optimizing storage with KV Store collection retention policy

Über dieses Dokument
Created:
2. August 2026
Keywords:
splunk
guide
consume
export
integration