| Name |
Enter a name for the sighting search configuration. |
| Vendor Name |
Name of the vendor. The details of the selected vendor is populated by default. For example, Splunk. |
| Integration Type |
Type of integration that you selected. For example, Threat Lookup. |
| Description |
Enter the description for the Splunk integration. For example, The Splunk enrichment integration aids in the investigation of a observable by supporting the querying of logs in your Splunk
deployment in relation to potentially malicious indicators.. |
| Integration Configuration |
| Splunk API Base URL |
The base URL you acquired from the Splunk site. |
| Link URL |
[Optional] The Link URL that links to the Splunk web interface, when available. |
| Username |
Your Intel Elasticsearch username. |
| Password |
Your Intel Elasticsearch password. |
| Max Rows |
The maximum number of rows you want to search. |
| Earliest Result (days) |
The earliest results you want to see in number of days. |
| Include raw data samples in search results |
Select this to include samples of raw data in your sightings search results. The amount of data returned depends on your setting in the number of rows of raw data property in Security Incident Response properties. |
| On Premises Deployment |
The On Premises Deployed environment. |
| MID Server |
Select Any to use any active MID Server, or select a specific MID Server name. |