Working with threat intelligence sources in Enterprise Security 8.5
Splunk Enterprise Security (ES) manages threat intelligence through two primary pillars: the native ES threat intelligence framework and the cloud-based Splunk Threat Intelligence Management (TIM). Knowing their role and how they relate to one another is key to building an effective threat surfacing strategy.
This series breaks the topic down into focused, hands-on articles suitable for detection engineers, admins, data architects and similar roles. Together they form an end-to-end guide on how threat intel is ingested, processed, matched, alerted on, and used to enrich investigations in ES 8.5.
About threat intelligence in Splunk Enterprise Security
Splunk Enterprise Security 8.5 offers two distinct onboarding methods of threat intel data.
- Native threat intelligence ingestion and processing is handled by components of the ES native Threat Intelligence Framework. The articles Configuring native threat intelligence sources in Enterprise Security 8.5 and Detecting threats and enriching investigations with native threat intelligence in Enterprise Security 8.5 offer an in-depth, technical walkthrough of native threat intel onboarding and give you a complete picture of how Threat Intelligence Framework performs threat detection and enrichment.
- Cloud-based intelligence is sourced from API feeds by a dedicated, Splunk-managed cloud service, Threat Intelligence Management (TIM Cloud). TIM Cloud embeds into the Threat Intelligence Framework, but it does not ship natively with ES. Instead, it requires a separate license and a Cloud Connect-enabled environment for on-premises deployments. Enriching threat intelligence with cloud-based sources in Enterprise Security 8.5 covers the technical aspects of TIM Cloud with a focus on its complementary and enhancing role to the native threat intel capabilities of ES. Because TIM Cloud is an ES integration, we recommend getting familiar with the first two articles to get a good grasp on ES threat intel foundations.
As Splunk works towards further integration of TIM Cloud into the existing, native ES threat engine, Splunk Help terminology has shifted to emphasize the core distinction between native and cloud-based intelligence. For that reason, in Splunk Help documentation as well as in our articles, you might come across the Threat Intelligence Framework referred to as native threat intelligence, and TIM Cloud as cloud-based intelligence.
Articles in this series
The articles below are designed to be read in order, but each one stands on its own if you're looking for guidance on a specific task.
| Article | What you'll learn |
|---|---|
| Configuring native threat intelligence sources in Enterprise Security 8.5 | Activate a prepackaged threat intel source (using PhishTank as an example), understand how TIF parses and routes downloaded data into *_intel collections, and add a custom feed using Malware Bazaar as an example. |
| Detecting threats and enriching investigations with native threat intelligence in Enterprise Security 8.5 | Unpack how threat matching searches surface IOC matches, how findings become alerts through detections like Threat Activity Detected, and how to capture IOCs as observables in the Investigation Intelligence tab. |
| Enriching threat intelligence with cloud-based sources in Enterprise Security 8.5 | Access and configure TIM Cloud feeds, understand how the tim_iocs collection stores cloud intel and connects to the native framework, search the collection with spath, and interpret TIM Cloud's normalized threat scoring. |
Additional resources
These resources might help you understand and implement this guidance:

