<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk ES taxii feed - AlienVault OTX config in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/684158#M11970</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194639"&gt;@efheem&lt;/a&gt;&amp;nbsp;Thanks for posting this!&amp;nbsp; Did this setup "just work" for you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With your configs, I see the files downloading in the logs, but it never finishes the first run. stating "&lt;SPAN class=""&gt;The downloaded &lt;/SPAN&gt;&lt;SPAN class=""&gt;taxii&lt;/SPAN&gt;&lt;SPAN class=""&gt; intelligence has a size that exceeds the configured &lt;/SPAN&gt;&lt;SPAN class=""&gt;max_size&lt;/SPAN&gt;&lt;SPAN class=""&gt; and will be discarded."&amp;nbsp; I've tried increasing the max to 500Mb in the lab, but still encounter the same problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 13 Apr 2024 10:35:30 GMT</pubDate>
    <dc:creator>steljas2</dc:creator>
    <dc:date>2024-04-13T10:35:30Z</dc:date>
    <item>
      <title>Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530384#M9477</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;Am having issues with the configuration of the AlienVault OTX feed in Splunk ES and would appreciate any help.&lt;/P&gt;&lt;P&gt;Have got my AlienVault OTX key ready but need help with the Threat Intel taxii feed settings in the web gui.&lt;/P&gt;&lt;P&gt;Data inputs&amp;nbsp;»&amp;nbsp;Intelligence Downloads&amp;nbsp;»&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Type: taxii&lt;/P&gt;&lt;P&gt;URL: &lt;A href="https://otx.alienvault.com/taxii/discovery" target="_blank" rel="noopener"&gt;https://otx.alienvault.com/taxii/discovery&lt;/A&gt;&lt;BR /&gt;POST Arguments: &lt;EM&gt;&amp;lt;this is where my key should be placed but how is this formatted??&amp;gt;&lt;BR /&gt;&lt;BR /&gt;-&amp;gt; have tried taxii_username="my_key"&amp;nbsp; in the post arguments to no avail. Just keep seeing the "TAXII feed polling starting" message on the "Threat Intelligence Audit" page.&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;Any help is greatly appreciated.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 07:45:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530384#M9477</guid>
      <dc:creator>oz_dg</dc:creator>
      <dc:date>2020-11-23T07:45:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530387#M9478</link>
      <description>&lt;P&gt;My advice is to install Splunk Add-on for Open Threat Exchange and Supporting Add-on for Open Threat Exchange. The installation is pretty straight forward and configuration guide can be found in the Details section of each Add-on on splunkbase.&lt;/P&gt;&lt;P&gt;I've managed to install and configure those add-ons in less than an hour.&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4336/" target="_blank"&gt;https://splunkbase.splunk.com/app/4336/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4337/" target="_blank"&gt;https://splunkbase.splunk.com/app/4337/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 07:46:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530387#M9478</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2020-11-23T07:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530529#M9484</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Many thanks for the reply.&lt;/P&gt;&lt;P&gt;We've been using those already but were kinda hoping we could move away from them (2yrs+ since last update on the github page + no SplunkApp Inspection pass mark) and use the general taxii feed input as it works fine for other feeds.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 06:52:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/530529#M9484</guid>
      <dc:creator>oz_dg</dc:creator>
      <dc:date>2020-11-24T06:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/531952#M9515</link>
      <description>&lt;P&gt;Hoping that there is way forward with this one.&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2020 02:33:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/531952#M9515</guid>
      <dc:creator>oz_dg</dc:creator>
      <dc:date>2020-12-04T02:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/670169#M11811</link>
      <description>&lt;P&gt;Just in case if someone is still looking for an answer to this, go to ES Threat Intelligence Management and click New -&amp;gt;TAXII&lt;BR /&gt;&lt;BR /&gt;Url : &lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://otx.alienvault.com/taxii/collections" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;https://otx.alienvault.com/taxii/collections&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;Post Arguments:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;collection=user_AlienVault taxii_username=xxxxxxxxxxxxxyourAPIKeyHerexxxxxxxxx  taxii_password=foo&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://otx.alienvault.com/taxii/collections" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2023 12:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/670169#M11811</guid>
      <dc:creator>efheem</dc:creator>
      <dc:date>2023-11-29T12:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/684158#M11970</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/194639"&gt;@efheem&lt;/a&gt;&amp;nbsp;Thanks for posting this!&amp;nbsp; Did this setup "just work" for you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With your configs, I see the files downloading in the logs, but it never finishes the first run. stating "&lt;SPAN class=""&gt;The downloaded &lt;/SPAN&gt;&lt;SPAN class=""&gt;taxii&lt;/SPAN&gt;&lt;SPAN class=""&gt; intelligence has a size that exceeds the configured &lt;/SPAN&gt;&lt;SPAN class=""&gt;max_size&lt;/SPAN&gt;&lt;SPAN class=""&gt; and will be discarded."&amp;nbsp; I've tried increasing the max to 500Mb in the lab, but still encounter the same problem.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2024 10:35:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/684158#M11970</guid>
      <dc:creator>steljas2</dc:creator>
      <dc:date>2024-04-13T10:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/699237#M12075</link>
      <description>&lt;P class="lia-align-left"&gt;Facing similar issue with Alien Vault threat feed ,i&lt;SPAN class=""&gt;ncreased the max size still it fails with error as "&amp;nbsp;&lt;SPAN&gt;Exception when polling TAXII feed. Any saved documents will be discarded" and "&lt;SPAN class=""&gt;The&lt;/SPAN&gt; &lt;SPAN class=""&gt;downloaded&lt;/SPAN&gt; &lt;SPAN class=""&gt;taxii&lt;/SPAN&gt; &lt;SPAN class=""&gt;intelligence&lt;/SPAN&gt; &lt;SPAN class=""&gt;has&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;size&lt;/SPAN&gt; &lt;SPAN class=""&gt;that&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeds&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;configured&lt;/SPAN&gt; &lt;SPAN class=""&gt;max_size&lt;/SPAN&gt; &lt;SPAN class=""&gt;and&lt;/SPAN&gt; &lt;SPAN class=""&gt;will&lt;/SPAN&gt; &lt;SPAN class=""&gt;be&lt;/SPAN&gt; &lt;SPAN class=""&gt;discarded.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="lia-align-left"&gt;Has anyone able to resolve this ?&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2024 00:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/699237#M12075</guid>
      <dc:creator>prathasj</dc:creator>
      <dc:date>2024-09-17T00:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES taxii feed - AlienVault OTX config</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/701790#M12123</link>
      <description>&lt;P&gt;I increased the limit several times, but eventually I got the same error. Do you know a way to see what data was received, for example, to do a search?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Oct 2024 10:07:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-taxii-feed-AlienVault-OTX-config/m-p/701790#M12123</guid>
      <dc:creator>user487596</dc:creator>
      <dc:date>2024-10-14T10:07:01Z</dc:date>
    </item>
  </channel>
</rss>

