#
Update Splunk Index
Danger, Will Robinson
Failure to update the index to the correct setting will cause no threat intel to be available in Splunk Enterprise Security.
The index definition is set by a search macro.
#
How to update
- Navigate to Settings > Advanced Search > Search Macros.
- From the "App" dropdown choose
SA-CrowdstrikeIntelIndicators
. - Set the "Owner" dropdown to
any
. - Click the macro named
crowdstrike_intel_index
to update the index definition.