Skip to main content

Spectra Intelligence App for Splunk SOAR Installation Guide

Overview

This guide will describe the process of installing and configuring the ReversingLabs Spectra Intelligence app for Splunk SOAR.

Prerequisites

Before you begin, ensure you have:

  1. A Splunk SOAR on-prem or Splunk SOAR Cloud instance versions 6.3, 6.2, or 6.1
  2. Administrator access to your Splunk environment
  3. A valid splunk.com username and password
  4. A valid ReversingLabs Spectra Intelligence username and password

Installation Steps

  1. Log in to your Splunk SOAR instance as an administrator
  2. Navigate to "Apps"
  3. Click "New Apps"
  4. Enter "ReversingLabs" in the search box
  5. Click "Install" next to "ReversingLabs TitaniumCloud v2"

Splunk SOAR App installation screen with ReversingLabs TitaniumCloud v2

Configuration Steps

  1. Navigate to the "Unconfigured Apps" section
  2. Click "Configure New Asset"

Splunk SOAR Unconfigured Apps section with Configure New Asset button

  1. Enter a custom name for the asset
  2. Click "Asset Settings"
  3. Enter the "https://data.reversinglabs.com" in the "TitaniumCloud URL" field
  4. Enter a valid Spectra Intelligence username and password in the associated fields

Splunk SOAR asset configuration form for TitaniumCloud connection

  1. Click the "Save" button"
  2. Click the "Test Connectivity" button to validate the settings

Splunk SOAR asset configuration Save and Test Connectivity buttons

Associated Playbooks

Two playbooks have been published to the Splunk SOAR community repository with this app, which are designed to help provide examples of using the actions provided by the ReversingLabs Spectra Intelligence app for Splunk SOAR.

Splunk SOAR example playbooks for ReversingLabs Spectra Intelligence integration

To use these playbooks, actions within the playbook need to point to the correct asset created in the earlier sections of this document. Click the playbook to open the editor, which will indicate a missing configuration. Click "View" to begin updating the playbook:

Splunk SOAR playbook editor showing missing asset configuration

Select the asset created earlier from the dropdown menu, then click "save":

Splunk SOAR playbook asset selection dropdown and save button

Click the "Save" button again, then enter a comment to save the updated playbook to the local repository:

Splunk SOAR playbook save dialog with comment field