<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding new threat list feed into splunk in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/470042#M99646</link>
    <description>&lt;P&gt;The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :&lt;BR /&gt;
/etc/apps/SA-ThreatIntelligence/contrib&lt;/P&gt;

&lt;P&gt;Problem fixed. &lt;/P&gt;</description>
    <pubDate>Mon, 18 Nov 2019 09:28:21 GMT</pubDate>
    <dc:creator>astatrial</dc:creator>
    <dc:date>2019-11-18T09:28:21Z</dc:date>
    <item>
      <title>Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/470041#M99645</link>
      <description>&lt;P&gt;Hello all, &lt;BR /&gt;
I am having issues with adding AlienVault OTX as a intelligence feed into splunk. &lt;BR /&gt;
At first, when i didn't configured the threat list as a taxii, it managed to download the threat list as a csv file. &lt;BR /&gt;
But now, i need to configure it as a taxii for parsing matters and it just stuck on that unhelpful message "TAXII feed polling starting". &lt;/P&gt;

&lt;P&gt;My feed configurations are : &lt;/P&gt;

&lt;P&gt;Type *&lt;BR /&gt;
taxii&lt;/P&gt;

&lt;P&gt;Description *&lt;BR /&gt;
Alien Vault OTX feed&lt;/P&gt;

&lt;P&gt;URL *&lt;BR /&gt;
&lt;A href="https://otx.alienvault.com/taxii/discovery" target="_blank"&gt;https://otx.alienvault.com/taxii/discovery&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Weight *&lt;BR /&gt;
1&lt;/P&gt;

&lt;P&gt;Interval&lt;BR /&gt;
43200&lt;/P&gt;

&lt;P&gt;POST arguments&lt;BR /&gt;
taxii_username="" taxii_password="poo"&lt;/P&gt;

&lt;P&gt;Maximum age&lt;BR /&gt;
-30d&lt;/P&gt;

&lt;P&gt;I am really frustrated and would really appreciate anyone's help. &lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:02:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/470041#M99645</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2020-09-30T02:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/470042#M99646</link>
      <description>&lt;P&gt;The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :&lt;BR /&gt;
/etc/apps/SA-ThreatIntelligence/contrib&lt;/P&gt;

&lt;P&gt;Problem fixed. &lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2019 09:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/470042#M99646</guid>
      <dc:creator>astatrial</dc:creator>
      <dc:date>2019-11-18T09:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/527437#M99647</link>
      <description>&lt;P&gt;Could you please give little bit more detail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Under&amp;nbsp;&lt;SPAN&gt;contrib directory I see many directories. One of these directories is&amp;nbsp;&lt;SPAN class="aui-icon aui-icon-small aui-iconfont-folder-filled"&gt;Directory libtaxii. Do you&amp;nbsp; mean to change this directory completely ? Is there any trusted source to get the&amp;nbsp;&amp;nbsp;&amp;nbsp;libtaxii 1.1.114&amp;nbsp; ?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 01 Nov 2020 07:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/527437#M99647</guid>
      <dc:creator>infosec2012074</dc:creator>
      <dc:date>2020-11-01T07:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/555036#M99648</link>
      <description>&lt;P&gt;could you elaborate a bit please&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jun 2021 07:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/555036#M99648</guid>
      <dc:creator>alexeyglukhov</dc:creator>
      <dc:date>2021-06-09T07:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/558506#M99649</link>
      <description>&lt;P&gt;I assume that was about this python library update&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/TAXIIProject/libtaxii" target="_blank" rel="noopener"&gt;https://github.com/TAXIIProject/libtaxii&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Jul 2021 06:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/558506#M99649</guid>
      <dc:creator>alexeyglukhov</dc:creator>
      <dc:date>2021-07-07T06:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Adding new threat list feed into splunk</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/558517#M99650</link>
      <description>&lt;P&gt;Thx for posting!!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 17:34:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Adding-new-threat-list-feed-into-splunk/m-p/558517#M99650</guid>
      <dc:creator>HowardGrace</dc:creator>
      <dc:date>2021-07-08T17:34:23Z</dc:date>
    </item>
  </channel>
</rss>

