<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Optiv Threat Intel fields in Security</title>
    <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414636#M12930</link>
    <description>&lt;P&gt;Hello friends.  &lt;/P&gt;

&lt;P&gt;I've recently installed optiv threat intel on my splunk indexer on my home network - trying to make it use logs from my DNS (Pihole).  &lt;/P&gt;

&lt;P&gt;I currently just get this: &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5892i4E11AA904A2665C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Here's an example of a log entry in how I have the fields defined. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5893iB69FC60768B0E244/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I'm trying to ascertain if I've set it up incorrectly, or if I just don't have any malicious activity on my network and "no news is good news." &lt;/P&gt;

&lt;P&gt;I'm relatively new to splunk - but I can run searches for top and rare for the dest_ip field - so I at least think I have the fields setup correctly.  Any light someone could cast on this would be much appreciated.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Oct 2018 14:11:32 GMT</pubDate>
    <dc:creator>zigity12</dc:creator>
    <dc:date>2018-10-11T14:11:32Z</dc:date>
    <item>
      <title>Optiv Threat Intel fields</title>
      <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414636#M12930</link>
      <description>&lt;P&gt;Hello friends.  &lt;/P&gt;

&lt;P&gt;I've recently installed optiv threat intel on my splunk indexer on my home network - trying to make it use logs from my DNS (Pihole).  &lt;/P&gt;

&lt;P&gt;I currently just get this: &lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5892i4E11AA904A2665C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Here's an example of a log entry in how I have the fields defined. &lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5893iB69FC60768B0E244/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I'm trying to ascertain if I've set it up incorrectly, or if I just don't have any malicious activity on my network and "no news is good news." &lt;/P&gt;

&lt;P&gt;I'm relatively new to splunk - but I can run searches for top and rare for the dest_ip field - so I at least think I have the fields setup correctly.  Any light someone could cast on this would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 14:11:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414636#M12930</guid>
      <dc:creator>zigity12</dc:creator>
      <dc:date>2018-10-11T14:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel fields</title>
      <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414637#M12931</link>
      <description>&lt;P&gt;App author here, &lt;BR /&gt;
You need to install the companion app, Optiv_TA_threat. See the included Readme pdf for detailed instructions. Post here if you get stuck. The companion app is the one that actually pulls the feeds from the internets. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:36:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414637#M12931</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2020-09-29T21:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel fields</title>
      <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414638#M12932</link>
      <description>&lt;P&gt;Thanks so much for your reply.&lt;/P&gt;

&lt;P&gt;I got the add on app installed - I didn't realize it was required, missed that in the readme.&lt;/P&gt;

&lt;P&gt;I'm still sitting on "no results found" - the heart of my question I guess is, is "no results found" code for "it's not working" or is it code for "there's no malicious traffic" (or both?)&lt;/P&gt;

&lt;P&gt;Thanks so much for your time.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2018 22:22:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414638#M12932</guid>
      <dc:creator>zigity12</dc:creator>
      <dc:date>2018-10-11T22:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel fields</title>
      <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414639#M12933</link>
      <description>&lt;P&gt;The app pulls the threat feeds down 4x per day. has the app been running that long? also check the troubleshooting tab&lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 18:17:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414639#M12933</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2018-10-12T18:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel fields</title>
      <link>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414640#M12934</link>
      <description>&lt;P&gt;That must have been it! The splash page is  populating with data now.  Thanks so much Derek! &lt;/P&gt;

&lt;P&gt;One last question if you have the time - &lt;IMG src="https://i.imgur.com/v2EwqZv.png" alt="alt text" /&gt;&lt;/P&gt;

&lt;P&gt;The large dashes above each section are where an alert would be displayed if an ip or domain shows up in my DNS logs, right?  &lt;/P&gt;</description>
      <pubDate>Fri, 12 Oct 2018 19:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Optiv-Threat-Intel-fields/m-p/414640#M12934</guid>
      <dc:creator>zigity12</dc:creator>
      <dc:date>2018-10-12T19:31:12Z</dc:date>
    </item>
  </channel>
</rss>

