Integration Overview: Splunk SOAR

Download App from Splunkbase

Find the latest version here: https://splunkbase.splunk.com/app/6347/.

12211221

The GreyNoise App download from SplunkBase

Install From Splunk SOAR Apps

From within Splunk SOAR, in the Apps UI, click the Install App button

14911491

Click the Install App button

Select the downloaded GreyNoise App bundle and click Install

14701470

Installing the GreyNoise App

21122112

GreyNoise App details

Configure an Instance of the GreyNoise Integration

The GreyNoise App will appear under the Unconfigured Apps menu. Select the Configure New Asset button. Give the asset a name and description.

11861186

Creating a new GreyNoise Asset

Under the Asset Settings section, add a GreyNoise API key and configure a GNQL to use for the On Poll action.

17561756

Adding the GreyNoise API Key

Performing an On-Demand IP Lookup

A variety of actions can be run on-demand, including IP Reputation (Noise), RIOT Lookup and Community API Lookup.

26482648

IP Reputation (Noise) Lookup results

26482648

RIOT IP Lookup results

21602160

Community IP Lookup results

Playbooks

In addition to the App, GreyNoise has also published playbooks that can help with common tasks. The playbooks can be downloaded from my.phantom.us and uploaded to your local phantom instance.

GreyNoise GNQL Enrichment

21102110

GreyNoise Update Severity from IP Reputation

33703370

GreyNoise IP Enrichment

15381538

GreyNoise On Poll Set Severity

20242024