---
title: "Installing and Configuring the Integration"
canonical: "https://docs.infoblox.com/space/DeploymentGuideTDwDDIforSplunkSOAR/1688404077/Installing%20and%20Configuring%20the%20Integration"
format: markdown
---
1. Download the [Infoblox Threat Defense with DDI](https://splunkbase.splunk.com/app/8036) from Splunkbase.

![image-20250916-111144.png](media://750fb8c8-b29d-45f2-a567-45032bc1b96d)

2. Navigate to the Apps page in your Splunk SOAR instance.

![image-20250916-110847.png](media://4b965546-d75b-4037-a0af-1ef93ecaf08d)

2. Click Install App.

![image-20250916-111420.png](media://1efe4cba-b185-4ff8-ba6a-b5d8ed0d836e)

3. Drag and drop a .tar or.rpm archive of the app into the file field, or click in the file field and navigate to the location of the app file on your system.

![image-20250916-111621.png](media://1cc15f3a-faee-47a3-8424-9df48ee01f5e)

4. Click Install.
5. After installing an app the new app is available on the Unconfigured Apps tab of the Apps page.

![image-20250916-111509.png](media://ca1bd456-4e0b-4b7c-a6b1-7443b33a3a1b)

6. To configure the integration, navigate to Unconfigured Apps. Click the Configure New Asset button next to the integration.

![image-20250916-111909.png](media://31e14c0e-d4ac-4c13-8f39-1ce915b8b115)

7. Give the Asset a name and description and click on Save.

![image-20250916-112111.png](media://c214748d-b7b3-45ac-869d-9f7d241278e0)

8. Enter the required parameters, select the type of data to ingest, and add any specific filters if required then click Save.

> ℹ️ This integration supports two types of data ingestion: **DNS Security Events** and **Infoblox IQ for Threat Defense.** If an ingestion type is not selected while configuring asset, data ingestion will not occur.  
> ℹ️ Only one data ingestion type can be configured per asset. To configure multiple data ingestion, set up multiple assets. Here are the configuration variable details for [DNS Security Events](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDIforSplunkSOAR/pages/1688600667) and [IQ for Threat Defense](https://infoblox-docs.atlassian.net/wiki/spaces/DeploymentGuideTDwDDIforSplunkSOAR/pages/1688600707)

![image-20250916-112259.png](media://3de37850-7c15-4619-b9a1-562c52c5d362)

9. In Ingest Setting, either select an existing label or create a new one for this source. Then click Save.

![image-20250916-112542.png](media://bc77bb10-107c-469a-b655-a7a7d69f6c66)

10. You can test the connectivity by navigating back to Asset Setting and clicking on Test Connectivity button.

![image-20250916-112831.png](media://905d3c72-68e5-445a-89a2-675883af6bd9)

11. Optionally you can add Approval Settings and Access Control to the asset you created.