Splunk SOAR | Use | Search#
The Splunk SOAR integration with EclecticIQ Intelligence Center (EIQ IC) allows you to search the Entities in IC from Splunk SOAR.
A search query will always return Entities with their:
Title
Type
Description
Source
Tags
Related Entities
Connected Observables with Type and Maliciousness
The table below shows the kinds of search strings you can enter, as well as the
filtering it applies to the results.
You can concatenate with AND logic.
Search string |
Filters to |
---|---|
(Partial) Entity Title |
Only Entities matching that Title. |
Entity Type (dropdown) |
Only Entities of that type. |
Observable Value |
Only Entities connected to that Observable. |
Alternatively, you can search for an exact Entity UUID, e.g.: a86f8393-eff6-4b31-b203-f63152be5a43
.
This retrieves that specific Entity (meaning additional filters like Type or Title aren’t necessary).