Available open intelligence sources for Splunk Enterprise Security
Open intelligence sources are sources that are freely available without any subscription requirement. Use the following table to find the supported observable types for each open intelligence source:
Intelligence source | Update type | Update frequency | Supported observable types |
---|---|---|---|
URLHaus | Feed-based | 60 minutes |
|
Abuse SSL IP Blacklist | Feed-based | 15 minutes |
|