---
title: "Infoblox Threat Defense – DNS Security Events"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDICortexXSOAR/1813151811/Infoblox%20Threat%20Defense%20%E2%80%93%20DNS%20Security%20Events"
format: markdown
---
# Purpose

Enable ingestion of DNS-based threat detections into Cortex for enhanced visibility and automated response.

This integration allows Cortex to fetch **DNS Security Events** from Infoblox Threat Defense Cloud. These events contain detailed information about potentially malicious domains, query types, and associated threat indicators.

# Configuration Steps

1. In Cortex, navigate to  
**Settings & Info → Integrations → Instances**.
2. Search for **Infoblox Threat Defense with DDI (Partner Contribution)** (installed from Marketplace).
3. Click **Add Instance**.
4. Enter an identifiable name such as **Infoblox Threat Defense – DNS Security Events**.
5. Provide the **Service API Key** generated from the Infoblox Cloud Portal under *Service API Keys*. *(Mandatory)*
6. Set the **Ingestion Type** to **DNS Security Events**.
7. (Optional) Configure additional parameters such as **Host**, **SSL**, and **Mapper** based on your environment.
8. Click **Test Connectivity** to validate the connection.
  1. A success message confirms communication with Infoblox Cloud.
  2. If the test fails, verify the API key and ensure outbound HTTPS access to Infoblox APIs is permitted.
9. Click **Save & Exit** to complete the setup.

![image-20251027-050325.png](media://22646477-ed78-4288-9dbf-8cc4c05389be)

![image-20251027-050402.png](media://934859a4-4f68-489e-b0b4-4a27280a7b6a)

# Capabilities

- Collects and normalizes DNS Security Event logs from Infoblox Threat Defense Cloud.
- Supports automation playbooks for blocking, enrichment, and remediation workflows.
- Displays domain reputation, threat categories, and timestamps for quick triage.

> ℹ️ You can refer to the **Help** section within the Cortex configuration page for detailed descriptions of parameters, valid values, and troubleshooting guidance specific to the DNS Security Events ingestion.