Skip to main content
Connect Splunk Enterprise Security (ES) to the TAXII 2.1 feed for automated threat intelligence ingestion.

Prerequisites

Configure TAXII feed

  1. In Splunk ES, go to Configure → Content → Threat Intelligence Management → New Threat Intelligence Collection.
  2. Select TAXII as the source type.
  3. Enter server details:
  1. Set polling interval to 15–60 minutes.
  2. Enable Use added_after for incremental updates.

Collections

STIX 2.1 objects

Reyhford returns STIX 2.1 indicator objects with:
  • ipv4-addr — attacking IP
  • network-traffic — port and protocol
  • autonomous-system — ASN and organization
  • location — country
  • indicator — STIX pattern, MITRE kill chain phase, confidence score
  • sighting — observation count, first and last seen
Splunk ES maps STIX indicators to notable events based on your correlation searches.

Verification

Troubleshooting

Verify the API key is active and passed as Bearer token. Discovery works without auth; objects require a key.
New sensors take a few minutes to produce enriched indicators. Check status.reyhford.com.
Switch collection from global-feed to ics-feed.