Create and manage safelist libraries in Splunk Enterprise Security

Note: This documentation topic on threat intelligence applies only to users using Threat Intelligence Management (Cloud), not native threat intelligence in Splunk Enterprise Security.

Create safelists in Splunk Enterprise Security to exclude particular indicators from your threat lists generated by Threat Intelligence Management (Cloud). Safelists ensure that threat lists remove indicators containing specific terms or phrases.

Follow these steps to add a safelist library:

  1. In Splunk Enterprise Security, select Configure and then Threat intelligence.
  2. Select Safelist libraries.
  3. Select + Add safelist library.
  4. Enter a name for the safelist.
  5. Enter each item one by one, or select Add safelist items in bulk to enter a full list of safelist items.
  6. Select Save.

After you add safelist libraries, you can edit or delete them from the list of libraries by selecting the pencil icon or the trash can icon.