
Jul 7, 2026
1.0.0
ThreatQ Versions >= 6.5.0
Splunk Export IOC Action
Overview
The Splunk Export IOC Action enables ThreatQ users to export supported indicators directly to Splunk using the Splunk HTTP Event Collector (HEC). Each indicator is sent as an individual JSON event enriched with relevant ThreatQ context, including status, confidence, score, source information, tags, timestamps, and other metadata, allowing security teams to correlate threat intelligence with operational data in Splunk for investigation and detection workflows.
The integration provides the following action:
- Splunk - Export Indicators - exports supported ThreatQ indicators and associated threat intelligence context to Splunk as individual JSON events through the Splunk HEC.
The integration is compatible with the following indicator types:
- CVE
- Email Address
- FQDN
- IP Address
- IPv6 Address
- MD5
- SHA-1
- SHA-256
- URL
Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.