<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I manually install Splunk ES threat lists ? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328946#M7765</link>
    <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;Anyone have a walk through on how I might install various threatlists to Splunk ES in a search head configuration? I can assume I just download the files to the search head deployer, just not sure where in the path I place them. &lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2017 01:30:41 GMT</pubDate>
    <dc:creator>daniel333</dc:creator>
    <dc:date>2017-04-13T01:30:41Z</dc:date>
    <item>
      <title>How do I manually install Splunk ES threat lists ?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328946#M7765</link>
      <description>&lt;P&gt;All, &lt;/P&gt;

&lt;P&gt;Anyone have a walk through on how I might install various threatlists to Splunk ES in a search head configuration? I can assume I just download the files to the search head deployer, just not sure where in the path I place them. &lt;/P&gt;

&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 01:30:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328946#M7765</guid>
      <dc:creator>daniel333</dc:creator>
      <dc:date>2017-04-13T01:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I manually install Splunk ES threat lists ?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328947#M7766</link>
      <description>&lt;P&gt;I haven't done much with ES, and even less with ES+SHC, but I'm curious if this doc is some of what you're looking for (there is a Cloud only marker on this version though... I wonder how much has changed):&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists#Add_OpenIOC_or_STIX_files_using_the_file_system"&gt;http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists#Add_OpenIOC_or_STIX_files_using_the_file_system&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 16:17:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328947#M7766</guid>
      <dc:creator>acharlieh</dc:creator>
      <dc:date>2017-04-13T16:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: How do I manually install Splunk ES threat lists ?</title>
      <link>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328948#M7767</link>
      <description>&lt;P&gt;Hello @daniel333,&lt;/P&gt;

&lt;P&gt;You're correct that you'd want to download the files (upload them, if adding a STIX/IOC file manually) to the deployer and then deploy them out. Treat it like a lookup file. &lt;/P&gt;

&lt;P&gt;The link that @acharlieh posted has the correct file path in it for that version and the previous one.&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists#Add_OpenIOC_or_STIX_files_using_the_file_system"&gt;http://docs.splunk.com/Documentation/ES/4.6.0/User/Configureblocklists#Add_OpenIOC_or_STIX_files_using_the_file_system&lt;/A&gt;&lt;BR /&gt;
If you go to the version of the documentation it will tell you if there is a specific path required. I believe in 4.5.0 is when we started requiring a specific file path. &lt;/P&gt;

&lt;P&gt;In the next version of ES (and the current cloud-only version) this is easier because you can upload the file and the software takes care of the rest, without worrying about a file system location. &lt;/P&gt;

&lt;P&gt;Let me know how that goes! I'm going to add a SHC-specific note to the documentation to make this clearer, thanks for your question!!&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2017 17:54:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-do-I-manually-install-Splunk-ES-threat-lists/m-p/328948#M7767</guid>
      <dc:creator>smoir_splunk</dc:creator>
      <dc:date>2017-04-13T17:54:47Z</dc:date>
    </item>
  </channel>
</rss>

