A Threat Intelligence Platform (TIP) like MISP, ThreatConnect, or Anomali aggregates, normalizes, and enriches threat intelligence from multiple sources (government feeds, ISACs, commercial vendors, open source). As an architect, you design the integration between the TIP and Splunk.
Splunk ingests threat intel via the Splunk Add-on for Threat Intelligence Management or via direct API ingestion. Indicators are stored in the `threat_activity` data model. Correlation searches then automatically enrich events against active indicators, firing Notable Events when a match is found. The architect must design the TTL (time-to-live) policy for indicators to avoid stale data degrading detection quality.