<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES Threat Intelligence in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-ES-Threat-Intelligence/m-p/363704#M5505</link>
    <description>&lt;P&gt;My question is in regards to the KVs in splunk ES.&lt;BR /&gt;
Since i am not a admin just a user, I have uploaded few Look up tables and outputting them into the local_http_ip or local_ip_intel file. I am able to do that successfully. Now my question is does http_intel or ip_intel suppose to automatically pull that information from the local csv? IF so, then how often is supposed to do that. &lt;/P&gt;

&lt;P&gt;Also, I have found another way of uploading my csv by  configure&amp;gt;data enrich&amp;gt; Threat intel uploads. It get uploaded to he KV store and  i can see event being generated in threat intel activity platfom but the issue with that it does not provide to much content about the IOCs. where in the csv i have information about the IOC. &lt;/P&gt;

&lt;P&gt;Does anyone know a better way of doing this? &lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:59:46 GMT</pubDate>
    <dc:creator>AbubakarShahid</dc:creator>
    <dc:date>2020-09-29T17:59:46Z</dc:date>
    <item>
      <title>Splunk ES Threat Intelligence</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/Splunk-ES-Threat-Intelligence/m-p/363704#M5505</link>
      <description>&lt;P&gt;My question is in regards to the KVs in splunk ES.&lt;BR /&gt;
Since i am not a admin just a user, I have uploaded few Look up tables and outputting them into the local_http_ip or local_ip_intel file. I am able to do that successfully. Now my question is does http_intel or ip_intel suppose to automatically pull that information from the local csv? IF so, then how often is supposed to do that. &lt;/P&gt;

&lt;P&gt;Also, I have found another way of uploading my csv by  configure&amp;gt;data enrich&amp;gt; Threat intel uploads. It get uploaded to he KV store and  i can see event being generated in threat intel activity platfom but the issue with that it does not provide to much content about the IOCs. where in the csv i have information about the IOC. &lt;/P&gt;

&lt;P&gt;Does anyone know a better way of doing this? &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/Splunk-ES-Threat-Intelligence/m-p/363704#M5505</guid>
      <dc:creator>AbubakarShahid</dc:creator>
      <dc:date>2020-09-29T17:59:46Z</dc:date>
    </item>
  </channel>
</rss>

