Part 2: Pair in Splunk Enterprise Security

Begin Part 2 only after you’ve completed Part 1: Obtain a Threat Intelligence Management (Cloud) tenant.

Follow these steps to pair:

  1. Log in to Splunk Enterprise Security.
  2. Select Configure then Threat intelligence.
  3. Select Pairing in the Threat Intelligence Management section.
  4. Select the link to Open Splunk Cloud Services.
  5. In Splunk Cloud Services, enter your tenant name. You can find your tenant name in the welcome email that your “ship to” contact received.
  6. Log in with your Splunk Cloud Services credentials.
  7. On the Settings page, copy your Access token.
  8. Return to Splunk Enterprise Security, and then enter your tenant name and access token on the Pairing page.
  9. Select Pair.
After the pairing is complete, you can find the pairing check mark along with the connection status. If for example you deleted your private key and need to re-enter it, you can do so by selecting Update tokens on the Pairing page.