TruSTAR integration for both Splunk Enterprise and Enterprise Security users. Installation Docs: https://support.trustar.co/article/x6yn7kzq52-install-tru-star-unified-for-splunk (video) Using this app to improve detection & triage: https://lantern.splunk.com/Splunk_Product_Learning_Guides/Splunk_Int_Mgmt/UnifiedApp_UseCase?mt-learningpath=intelmgmtunifiedappconfig# ** Notes to SplunkCloud SRE: - This app must be installed on searchheads (NOT IDM), and includes a modinput, which must be allowed to run on the searchhead. - The modinput contains checks to ensure that it will only run on the cluster Captain in and SHC deployment. - The app contains modactions that need to be available on all SHC nodes, so the app needs to be installed on all SHC nodes. - The modinput fetches cyber threat observables from TruSTAR's REST API and posts them to the searchheads' kvstores using the kvstore "batch_save" endpoint, not an index as most modinputs do. This is why it must run on the searchheads, not an IDM. There is no config option that would allow the user to tell the modinput to post the observables to that endpoint on a different host, it's hard-coded to post to "localhost". References for exceptions to "no modinputs on SHs policy": - Case #1685202 "Vet and Install TruSTAR App for Splunk ES." (Circa April 7, 2020) (TruSTAR App for Splunk ES was this app's predecessor) - Case # 2646540
(1)
TruSTAR integration for both Splunk Enterprise and Enterprise Security users. Installation Docs: https://support.trustar.co/article/x6yn7kzq52-install-tru-star-unified-for-splunk (video) Using this app to improve detection & triage: https://lantern.splunk.com/Splunk_Product_Learning_Guides/Splunk_Int_Mgmt/UnifiedApp_UseCase?mt-learningpath=intelmgmtunifiedappconfig# ** Notes to SplunkCloud SRE: - This app must be installed on searchheads (NOT IDM), and includes a modinput, which must be allowed to run on the searchhead. - The modinput contains checks to ensure that it will only run on the cluster Captain in and SHC deployment. - The app contains modactions that need to be available on all SHC nodes, so the app needs to be installed on all SHC nodes. - The modinput fetches cyber threat observables from TruSTAR's REST API and posts them to the searchheads' kvstores using the kvstore "batch_save" endpoint, not an index as most modinputs do. This is why it must run on the searchheads, not an IDM. There is no config option that would allow the user to tell the modinput to post the observables to that endpoint on a different host, it's hard-coded to post to "localhost". References for exceptions to "no modinputs on SHs policy": - Case #1685202 "Vet and Install TruSTAR App for Splunk ES." (Circa April 7, 2020) (TruSTAR App for Splunk ES was this app's predecessor) - Case # 2646540
Categories
Created By
Type
Downloads
Featured in Collection
Resources