---
title: "Infoblox Threat Defense – SOC Insights"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDICortexXSOAR/1815642123/Infoblox%20Threat%20Defense%20%E2%80%93%20SOC%20Insights"
format: markdown
---
# Purpose

Enable incident correlation and enrichment for SOC operations.

The SOC Insights integration allows Cortex to ingest enriched incidents directly from Infoblox Threat Defense Cloud, providing enhanced visibility into user-attributed threats and DNS-based indicators.

# Configuration Steps

1. In Cortex, navigate to  
**Settings & Info → Integrations → Instances**.
2. Search for **Infoblox Threat Defense with DDI (Partner Contribution)** (installed from Marketplace).
3. Click **Add Instance**.
4. Enter an identifiable name such as **Infoblox Threat Defense – SOC Insights**.
5. Provide the **Service API Key** generated from the Infoblox Cloud Portal under *Service API Keys*. *(Mandatory)*
6. Select **Ingestion Type → SOC Insight**.
7. (Optional) Configure other parameters like **Host**, **SSL**, or **Mapper** based on your environment preferences.
8. Click **Test Connectivity** to validate the connection between Cortex and Infoblox Cloud.
  1. If successful, a green confirmation message appears indicating *“Test passed successfully.”*
  2. If it fails, verify the Service API Key and ensure the API endpoint is reachable from Cortex.

Once validated, click **Save & Exit**.  


![image-20251027-045648.png](media://95b6cef5-34e0-466d-8013-821d7b9126e5)

![image-20251027-045533.png](media://6ae176db-a7db-441f-bbcc-f385ca354603)

# Capabilities

- Consolidates incidents within Cortex.
- Allows automation playbooks to query SOC Insights data.
- Displays threat severity and analyst comments.

> ℹ️ You can refer to the **Help** section available within the Cortex configuration page for detailed descriptions of each parameter, valid values, and guidance on setting up the integration.