<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why can't I download from OpenCTI Stream Feed into Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742920#M118023</link>
    <description>&lt;P&gt;Ah yes good spot&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162406"&gt;@goji&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By editing in the config file directly you are bypassing the validation that is built-in that stops you saving it via the UI. At this point the Verify=true in the python code has no effect because its using http anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for letting me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Mar 2025 10:12:17 GMT</pubDate>
    <dc:creator>livehybrid</dc:creator>
    <dc:date>2025-03-28T10:12:17Z</dc:date>
    <item>
      <title>Why can't I download from OpenCTI Stream Feed into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742772#M117988</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;I just want to input OpenCTI feed from OpenCTI to Splunk.&lt;BR /&gt;&lt;BR /&gt;I followed installation instruction.&lt;BR /&gt;&lt;A href="https://splunkbase.splunk.com/app/7485" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/7485&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;But, there is an error in _internal index as follows.&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN class=""&gt;2025-03-27&lt;/SPAN&gt; &lt;SPAN class=""&gt;16:50:02&lt;/SPAN&gt;,&lt;SPAN class=""&gt;889&lt;/SPAN&gt; &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;pid=17581&lt;/SPAN&gt; &lt;SPAN class=""&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class=""&gt;file=base_modinput.py:log_error:309&lt;/SPAN&gt; | &lt;SPAN class=""&gt;Error&lt;/SPAN&gt; &lt;SPAN class=""&gt;in&lt;/SPAN&gt; &lt;SPAN class=""&gt;ListenStream&lt;/SPAN&gt; &lt;SPAN class=""&gt;loop&lt;/SPAN&gt;, &lt;SPAN class=""&gt;exit&lt;/SPAN&gt;, &lt;SPAN class=""&gt;reason:&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTPSConnectionPool&lt;/SPAN&gt;(&lt;SPAN class=""&gt;host=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;192.168.0.15&lt;/SPAN&gt;', &lt;SPAN class=""&gt;port=8080&lt;/SPAN&gt;)&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Max&lt;/SPAN&gt; &lt;SPAN class=""&gt;retries&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;url:&lt;/SPAN&gt; &lt;SPAN class=""&gt;/stream/2cfe507d-1345-402d-82c7-eb8939228bf0&lt;/SPAN&gt;?&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;recover=2025-03-27T07:50&lt;/SPAN&gt;:&lt;SPAN class=""&gt;02Z&lt;/SPAN&gt;&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Caused&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;SSLError&lt;/SPAN&gt;(&lt;SPAN class=""&gt;SSLError&lt;/SPAN&gt;(&lt;SPAN class=""&gt;1&lt;/SPAN&gt;, '[&lt;SPAN class=""&gt;SSL:&lt;/SPAN&gt; &lt;SPAN class=""&gt;UNKNOWN_PROTOCOL&lt;/SPAN&gt;] &lt;SPAN class=""&gt;unknown&lt;/SPAN&gt; &lt;SPAN class=""&gt;protocol&lt;/SPAN&gt; (&lt;SPAN class=""&gt;_ssl.c:1106&lt;/SPAN&gt;)')))&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;BR /&gt;And I was able to access OpenCTI feeds using curl in Splunk enfironement and browser as well, but I can't access the OpenCTI stream using StreamID from Splunk to fetch the data. I think SSL is one of the issues.&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;BR /&gt;Please tell me if you know how to fetch the OpenCTI data to Splunk&lt;/DIV&gt;</description>
      <pubDate>Thu, 27 Mar 2025 08:02:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742772#M117988</guid>
      <dc:creator>goji</dc:creator>
      <dc:date>2025-03-27T08:02:34Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't I download from OpenCTI Stream Feed into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742780#M117993</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162406"&gt;@goji&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Having checked the python code within this app - it looks like it is forcing SSL Verification when connecting to the OpenCTI endpoint.&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;response = helper.send_http_request(url, method, parameters=None, payload=None,
                                        headers=None, cookies=None, verify=True, cert=None,
                                        timeout=None, use_proxy=True)&lt;/LI-CODE&gt;&lt;P&gt;This means that you would need to provide a OpenCTI URL on a DNS name with a valid SSL Certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When you tried to connect using curl, did you need to pass param like "-k" to skip SSL Verification?&lt;/P&gt;&lt;P&gt;Are you able to use a DNS name and add a valid SSL certificate to the OpenCTI server? If not then I think the only other option would be to modify the script to turn off SSL verification (Its a shame the app author hasnt provided this option). The issue with this is it can leave you with a fragile environment, in that if you upgrade the app in the future then it will override your changes.&lt;/P&gt;&lt;P&gt;If you want to test this approach then you can try making the following modifications - but remember the caveats (This is obviously sub-optimal!)&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TA-opencti-add-on/bin/input_module_opencti_indicators.py - Lines 224-226

    response = helper.send_http_request(url, method, parameters=None, payload=None,
headers=None, cookies=None, verify=True, cert=None,
timeout=None, use_proxy=True)

Change verify=True to verify=False&lt;/LI-CODE&gt;&lt;P&gt;And the modalert:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;TA-opencti-add-on/bin/ta_opencti_add_on/alert_actions_base.py - Line 108
    def send_http_request(self, url, method, parameters=None, payload=None, headers=None, cookies=None, verify=True, cert=None, timeout=None, use_proxy=True):

Again, change verify=True to verify=False&lt;/LI-CODE&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Will&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 08:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742780#M117993</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-27T08:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't I download from OpenCTI Stream Feed into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742883#M118015</link>
      <description>&lt;P&gt;After all, there is such a thing as the norm not being the norm,&lt;BR /&gt;By default, the opencti URL is &lt;A href="http://ip:8080" target="_blank"&gt;http://ip:8080&lt;/A&gt; (not https)&lt;BR /&gt;Splunk's OpenCTI forces you to enter only “https://” as you are operating.&lt;BR /&gt;And I can't change it back to “http”. So I guess there was an error.&lt;BR /&gt;I edited the URL of the file ta_opencti_add_on_settings.conf in ta directly (https -&amp;gt; https) and restarted.&lt;BR /&gt;Then I was able to load the data. Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 02:20:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742883#M118015</guid>
      <dc:creator>goji</dc:creator>
      <dc:date>2025-03-28T02:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why can't I download from OpenCTI Stream Feed into Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742920#M118023</link>
      <description>&lt;P&gt;Ah yes good spot&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162406"&gt;@goji&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;By editing in the config file directly you are bypassing the validation that is built-in that stops you saving it via the UI. At this point the Verify=true in the python code has no effect because its using http anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks for letting me know.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 10:12:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-can-t-I-download-from-OpenCTI-Stream-Feed-into-Splunk/m-p/742920#M118023</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-28T10:12:17Z</dc:date>
    </item>
  </channel>
</rss>

