Kaspersky Threat Intelligence Portal for Splunk is accessible by browser. The certificate for Kaspersky Threat Intelligence Portal must be imported to the browser before you can use the app.
To use Kaspersky Threat Intelligence Portal:
Import the Kaspersky-Threat-Intelligence-Portal-for-Splunk.tar.gz file that you received from your technical account manager (TAM) or downloaded from the Splunk web site.

Kaspersky Threat Intelligence Portal for Splunk
The Kaspersky Threat Intelligence Portal for Splunk dashboard opens.

Kaspersky Threat Intelligence Portal for Splunk dashboard
*), which means all source typesFor example, if an IP address field is selected and you want to search for IP addresses that contain 192.0.2. as a substring, specify 192.0.2. in the Value filter field.
By default, the Value filter field contains the wildcard character (*), and all values for the specified field will be included in the search result.
The Search results table will contain data relevant for the query.

Kaspersky Threat Intelligence Portal for Splunk search result

Threat intelligence sample
For more information about Kaspersky Threat Intelligence Portal, refer to the documentation displayed after you click the HELP link in the upper right area of the Kaspersky Threat Intelligence Portal window. The current Kaspersky Threat Intelligence Portal for Splunk documentation is accessible through the Kaspersky Threat Intelligence Portal for Splunk on-line documentation link in the lower right area of the app window.
Page top