Splunk alert action app for exporting indicators from Splunk to Anomali ThreatStream.
git clone https://github.com/vavarachen/ts_webhook_alert.git
tar -czf ts_webhook_alert.tar.gz ts_webhook_alert
Upload the tar.gz file to Splunk Search Head (Apps > Manage Apps > Install app from file)
Find app ("Anomali Threatstream Indicator Export") and click "Set up"