Loading

Flashpoint Integration for Elastic

Version 0.1.0 (View all)
Subscription level
What's this?
Basic
Developed by
What's this?
Elastic
Ingestion method(s) API
Minimum Kibana version(s) 9.0.0
8.18.0
The Flashpoint integration v0.1.0 is in beta

To use beta integrations, go to the Integrations page in Kibana, scroll down, and toggle on the Display beta integrations option.

Flashpoint is a comprehensive threat intelligence platform that delivers actionable insights from dark web, deep web, and technical sources. It combines human-curated intelligence with automated collection to help organizations identify emerging threats, monitor adversary activity, and assess cyber risk with enriched context.

The Flashpoint integration for Elastic collects alerts, indicators and vulnerabilities from the Flashpoint Ignite API and visualizes them in Kibana.

The Flashpoint integration is compatible with Ignite API version 1.2.

This integration periodically queries the Flashpoint Ignite API to retrieve logs.

This integration collects log messages of the following type:

  • Alert: Collects alert logs from the Flashpoint Ignite API (endpoint: /alert-management/v1/notifications),
  • Indicator: Collects indicator logs from the Flashpoint Ignite API (endpoint: /technical-intelligence/v2/indicators),
  • Vulnerabilities: Collects vulnerability logs from the Flashpoint Ignite API (endpoint: /vulnerability-intelligence/v1/vulnerabilities),
Note

This integration uses Elastic transforms to deduplicate incident data and maintain the latest view of each incident for analysis and reporting.

Integrating Flashpoint with Elastic SIEM provides centralized visibility into threat intelligence Alerts, Indicators, and Vulnerabilities, enabling efficient monitoring, investigation, and risk assessment within Kibana dashboards.

For Alerts, the dashboard presents key metrics such as Total Alerts and Alert Trends Over Time, helping analysts quickly detect activity spikes and monitor evolving threat patterns.

For Indicators, the dashboard highlights Total Indicators and Indicators by Type, providing insight into indicator volume and classification for effective threat analysis.

For Vulnerabilities, the dashboard presents Total Vulnerabilities and key breakdowns by Severity and Status, helping security teams assess exposure levels and prioritize remediation efforts.

Interactive filtering controls allow analysts to drill down across alerts, indicators, and vulnerabilities, supporting streamlined investigation and prioritization workflows within a unified threat intelligence view.

This integration installs Elastic latest transforms. For more details, check the Transform setup and requirements.

To collect data through the Flashpoint Ignite API, you need to provide an API Token. Authentication is handled using the API Token, which serves as the required credential.

  1. Log in to the Flashpoint Instance.
  2. Click on your profile icon in the top-right corner and select Manage API Tokens.
  3. Click Generate Token.
  4. Enter a name for the API token and click Generate Token.
  5. Copy and securely store the generated API token for use in the integration configuration.

This integration supports both Elastic Agentless-based and Agent-based installations.

Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to Agentless integrations and the Agentless integrations FAQ.

Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.

Elastic Agent must be installed. For more details, check the Elastic Agent installation instructions. You can install only one Elastic Agent per host.

  1. In the top search bar in Kibana, search for Integrations.

  2. In the search bar, type Flashpoint.

  3. Select the Flashpoint integration from the search results.

  4. Select Add Flashpoint to add the integration.

  5. Enable and configure only the collection methods which you will use.

    • To Collect logs from Flashpoint API, you'll need to:

      • Configure API Token.
      • Adjust the integration configuration parameters if required, including the Initial Interval, Interval, Page Size etc. to enable data collection.
  6. Select Save and continue to save the integration.

  1. If vulnerability data collection is slow or fails with context deadline exceeded, reduce the Page Size and increase the HTTP Client Timeout.
  1. In the top search bar in Kibana, search for Dashboards.
  2. In the search bar, type Flashpoint, and verify the dashboard information is populated.
  1. In the top search bar in Kibana, search for Transforms.
  2. Select the Data / Transforms from the search results.
  3. In the search bar, type ti_flashpoint.
  4. All transforms from the search results should indicate Healthy under the Health column.

For more information on architectures that can be used for scaling this integration, check the Ingest Architectures documentation.

These input is used in the integration:

This integration dataset uses the following API:

  • List Alerts (endpoint: /alert-management/v1/notifications)|
  • List Indicators (endpoint: /technical-intelligence/v2/indicators)
  • List Vulberabilities (endpoint: /vulnerability-intelligence/v1/vulnerabilities)

This integration includes one or more Kibana dashboards that visualizes the data collected by the integration. The screenshots below illustrate how the ingested data is displayed.