Skip to main content


Splunk Lantern

Splunk Intelligence Management (TruSTAR) - Unified App: Validate Download of Indicators

In this video, we’ll show you how to validate that your Unified App has successfully downloaded observables that have been identified as potential Indicators of Compromise from Splunk Intelligence Management to Splunk Enterprise or Splunk Enterprise Security KV Stores. 

Click the "+" below to expand the configuration path and jump to the section you need. Each step is explained in a short video:

Splunk Intelligence Management (TruSTAR) - Setting up the Unified App for Splunk ES
Pages: 5