<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Enterprise Security Intelligence Github Data Pulling- Why can't I see information? in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-Security-Intelligence-Github-Data-Pulling-Why/m-p/648063#M17052</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want support to know why I am not able to see lookup for my created Threat Intelligence Management Source under Splunk Enterprise Security pulled from Github.&lt;/P&gt;
&lt;P&gt;I am trying to get mac and its vendor details as intelligence after using the feature of "Threat Intelligence Management"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My configurations are below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Creation of source under Threat Intelligence Manager with "Line Oriented" selection.&lt;/P&gt;
&lt;P&gt;2. Input name mac_vendor with description as mac_vendor, type also mac_vendor with Github URL details:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Unchecked "Threat Intelligence" Box.&lt;/P&gt;
&lt;P&gt;4. File Parser Auto&lt;/P&gt;
&lt;P&gt;5. Delimiting regular expression setting as : ,&lt;/P&gt;
&lt;P&gt;6. Ignoring regular expression setting as :&amp;nbsp;(^#|^\s*$)&lt;/P&gt;
&lt;P&gt;7. field section: mac:$1,vendor:$2&lt;/P&gt;
&lt;P&gt;8. skip header lines : 0&lt;/P&gt;
&lt;P&gt;with rest configured as default only.&lt;/P&gt;
&lt;P&gt;Sample Event showing successful file download:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;pid=28775&lt;/SPAN&gt; &lt;SPAN class=""&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class=""&gt;file=threatlist.py:download_threatlist_file:549&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;stanza=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;mac_ioc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;retries_remaining=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;status=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;threat&lt;/SPAN&gt; &lt;SPAN class=""&gt;list&lt;/SPAN&gt; &lt;SPAN class=""&gt;downloaded&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;file=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/opt/splunk/var/lib/splunk/modinputs/threatlist/mac_ioc&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;678565&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;url=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://gist.githubusercontent.com/aallan/b4bb86db86079509e6159810ae9bd3e4/raw/846ae1b646ab0f4d646af9115e47365f4118e5f6/mac-vendor.txt" target="_blank" rel="noopener"&gt;https://gist.githubusercontent.com/aallan/b4bb86db86079509e6159810ae9bd3e4/raw/846ae1b646ab0f4d646af9115e47365f4118e5f6/mac-vendor.txt&lt;/A&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What I am missing to see this information in Splunk S.A Intelligence?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 14:00:39 GMT</pubDate>
    <dc:creator>joomla</dc:creator>
    <dc:date>2023-06-26T14:00:39Z</dc:date>
    <item>
      <title>Splunk Enterprise Security Intelligence Github Data Pulling- Why can't I see information?</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Enterprise-Security-Intelligence-Github-Data-Pulling-Why/m-p/648063#M17052</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I want support to know why I am not able to see lookup for my created Threat Intelligence Management Source under Splunk Enterprise Security pulled from Github.&lt;/P&gt;
&lt;P&gt;I am trying to get mac and its vendor details as intelligence after using the feature of "Threat Intelligence Management"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My configurations are below:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Creation of source under Threat Intelligence Manager with "Line Oriented" selection.&lt;/P&gt;
&lt;P&gt;2. Input name mac_vendor with description as mac_vendor, type also mac_vendor with Github URL details:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3. Unchecked "Threat Intelligence" Box.&lt;/P&gt;
&lt;P&gt;4. File Parser Auto&lt;/P&gt;
&lt;P&gt;5. Delimiting regular expression setting as : ,&lt;/P&gt;
&lt;P&gt;6. Ignoring regular expression setting as :&amp;nbsp;(^#|^\s*$)&lt;/P&gt;
&lt;P&gt;7. field section: mac:$1,vendor:$2&lt;/P&gt;
&lt;P&gt;8. skip header lines : 0&lt;/P&gt;
&lt;P&gt;with rest configured as default only.&lt;/P&gt;
&lt;P&gt;Sample Event showing successful file download:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;INFO&lt;/SPAN&gt; &lt;SPAN class=""&gt;pid=28775&lt;/SPAN&gt; &lt;SPAN class=""&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class=""&gt;file=threatlist.py:download_threatlist_file:549&lt;/SPAN&gt;&lt;SPAN&gt; | &lt;/SPAN&gt;&lt;SPAN class=""&gt;stanza=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;mac_ioc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;retries_remaining=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;3&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;status=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;threat&lt;/SPAN&gt; &lt;SPAN class=""&gt;list&lt;/SPAN&gt; &lt;SPAN class=""&gt;downloaded&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;file=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;/opt/splunk/var/lib/splunk/modinputs/threatlist/mac_ioc&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;bytes=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;678565&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;url=&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://gist.githubusercontent.com/aallan/b4bb86db86079509e6159810ae9bd3e4/raw/846ae1b646ab0f4d646af9115e47365f4118e5f6/mac-vendor.txt" target="_blank" rel="noopener"&gt;https://gist.githubusercontent.com/aallan/b4bb86db86079509e6159810ae9bd3e4/raw/846ae1b646ab0f4d646af9115e47365f4118e5f6/mac-vendor.txt&lt;/A&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;What I am missing to see this information in Splunk S.A Intelligence?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 14:00:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Enterprise-Security-Intelligence-Github-Data-Pulling-Why/m-p/648063#M17052</guid>
      <dc:creator>joomla</dc:creator>
      <dc:date>2023-06-26T14:00:39Z</dc:date>
    </item>
  </channel>
</rss>

