Create and manage safelist libraries in Splunk Enterprise Security

Note: This documentation topic on threat intelligence applies only to users with access to the threat intelligence management (cloud) system, and not the threat intelligence management system, in Splunk Enterprise Security

Create safelists in Splunk Enterprise Security to exclude particular indicators from your threat lists generated by the threat intelligence management (cloud) system. Safelists ensure that threat lists remove indicators containing specific terms or phrases.

Follow these steps to add a safelist library:

  1. In Splunk Enterprise Security, select Configure and then Intelligence.
  2. In the Threat intelligence management (cloud) section, select Safelist libraries.
  3. Select + Add safelist library.
  4. Enter a name for the safelist.
  5. Enter each item one by one, or select Add safelist items in bulk to enter a full list of safelist items.
  6. Select Save.

After you add safelist libraries, you can edit or delete them from the list of libraries by selecting the pencil icon or the trash can icon.