<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248717#M1758</link>
    <description>&lt;P&gt;On the Soltra Edge Server:&lt;/P&gt;

&lt;P&gt;1)  Create your site : This is your connection to FS-ISAC with your various polling rules - &lt;BR /&gt;
2) In the Feeds TAB create a new feed - &lt;EM&gt;This is what Spunk will connect to e.g create a feed called " MYFEED" &lt;A href="http://127.0.0.1/taxii-discovery-service"&gt;http://127.0.0.1/taxii-discovery-service&lt;/A&gt; .&lt;/EM&gt;&lt;BR /&gt;
3) Make sure you have a user name, password and a trust group established &lt;/P&gt;

&lt;P&gt;On the Splunk side :&lt;BR /&gt;
1) your TAXII Server entry=  IP address or Host Name of your SOLTRA Box &lt;BR /&gt;
2) PORT 80&lt;BR /&gt;
3)  /taxii-discovery-service/  e.g. full url would be &lt;A href="http://192.xxx.xxx.xxx/taxii-discovery-service/admin.MYFEED"&gt;http://192.xxx.xxx.xxx/taxii-discovery-service/admin.MYFEED&lt;/A&gt;&lt;BR /&gt;
4) Userid = which ever one your created associated to the new feed on Soltra&lt;BR /&gt;
5) Password = Whatever password &lt;/P&gt;

&lt;P&gt;Let me know how you make out . &lt;/P&gt;</description>
    <pubDate>Fri, 30 Oct 2015 17:03:54 GMT</pubDate>
    <dc:creator>klaxdal</dc:creator>
    <dc:date>2015-10-30T17:03:54Z</dc:date>
    <item>
      <title>How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248714#M1755</link>
      <description>&lt;P&gt;1st time configuring a feed in the Splunk App for Enterprise Security and I'm spinning my wheels.  HELP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;  I have the Soltra server running and downloading the FS-ISAC feed, but how to I set it up in Splunk? By setup, I mean syntax in the Splunk URL &amp;amp; post arguments.  &lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2015 12:50:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248714#M1755</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2015-09-29T12:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248715#M1756</link>
      <description>&lt;P&gt;Did you ever make progress on this?  I just started building out my Soltra box with the idea to do the same thing.  As I run across more relevant info I'll post here.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248715#M1756</guid>
      <dc:creator>austinparker</dc:creator>
      <dc:date>2015-10-29T19:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248716#M1757</link>
      <description>&lt;P&gt;NO!  I have the edge server still running I've asked several folks on here, on Soltra, and even dug though the fsisac forums and asked an engineer there.  I'm sure I have a config issue, but the documentation leaves me stranded.  Let me know what you find as I'm to the point now of asking my pro-serve person to ask folks that he has run across!....&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 19:44:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248716#M1757</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2015-10-29T19:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248717#M1758</link>
      <description>&lt;P&gt;On the Soltra Edge Server:&lt;/P&gt;

&lt;P&gt;1)  Create your site : This is your connection to FS-ISAC with your various polling rules - &lt;BR /&gt;
2) In the Feeds TAB create a new feed - &lt;EM&gt;This is what Spunk will connect to e.g create a feed called " MYFEED" &lt;A href="http://127.0.0.1/taxii-discovery-service"&gt;http://127.0.0.1/taxii-discovery-service&lt;/A&gt; .&lt;/EM&gt;&lt;BR /&gt;
3) Make sure you have a user name, password and a trust group established &lt;/P&gt;

&lt;P&gt;On the Splunk side :&lt;BR /&gt;
1) your TAXII Server entry=  IP address or Host Name of your SOLTRA Box &lt;BR /&gt;
2) PORT 80&lt;BR /&gt;
3)  /taxii-discovery-service/  e.g. full url would be &lt;A href="http://192.xxx.xxx.xxx/taxii-discovery-service/admin.MYFEED"&gt;http://192.xxx.xxx.xxx/taxii-discovery-service/admin.MYFEED&lt;/A&gt;&lt;BR /&gt;
4) Userid = which ever one your created associated to the new feed on Soltra&lt;BR /&gt;
5) Password = Whatever password &lt;/P&gt;

&lt;P&gt;Let me know how you make out . &lt;/P&gt;</description>
      <pubDate>Fri, 30 Oct 2015 17:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248717#M1758</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2015-10-30T17:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248718#M1759</link>
      <description>&lt;P&gt;Getting closer!  Splunk says I'm missing collection.  Digging through the Soltra documentation again, case I missed something...&lt;/P&gt;

&lt;P&gt;2015-11-02 14:36:19,798 ERROR pid=21869 tid=MainThread file=threatlist.py:download_taxii:248 | status="Exception when polling TAXII feed." Traceback (most recent call last): File "/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/threatlist.py", line 231, in download_taxii for count, content_block in enumerate(handler.run(args, handler_args)): File "/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/taxii_client/&lt;STRONG&gt;init&lt;/STRONG&gt;.py", line 123, in run parsed_args = self.&lt;EM&gt;parse_args(args, handler_args) File "/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/taxii_client/&lt;/EM&gt;&lt;EM&gt;init&lt;/EM&gt;_.py", line 95, in _parse_args raise TaxiiHandlerException('Invalid arguments for TAXII service (missing collection).') TaxiiHandlerException: Invalid arguments for TAXII service (missing collection).&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 07:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248718#M1759</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2020-09-29T07:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248719#M1760</link>
      <description>&lt;P&gt;ok this was a complete PITA from the work GO.   klaxdal thanks a ton for pointing me in the right direction it was excatly what I was looking for.  I still had a couple challenges like my Edge server decided to stop working on Oct 22, then I had the challenge if fighting the 2 factor cert within Edge.  I had to hard code the username an password instead of using the cred manager in Splunk?  I may try to back that off tomorrow as I was giddy to actually see data in Splunk ES....&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 20:00:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248719#M1760</guid>
      <dc:creator>cdupuis123</dc:creator>
      <dc:date>2015-11-04T20:00:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248720#M1761</link>
      <description>&lt;P&gt;Alright ! If you need any help msg me . &lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 20:02:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248720#M1761</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2015-11-04T20:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248721#M1762</link>
      <description>&lt;P&gt;I've had some success, but I'm still not quite there.  At this point I'm not sure if I've passed the parameters wrong in splunk for if I've done it wrong on Soltra.&lt;/P&gt;

&lt;P&gt;This is the message I get from Splunk in ES on the Threat Intelligence Audit&lt;/P&gt;

&lt;P&gt;status="Retrieved documents from TAXII feed" count="0" stanza="Soltra Edge" collection="admin.IPWatchlist"&lt;/P&gt;

&lt;P&gt;This is better than the error of being stuck on Polling which I had before.&lt;/P&gt;

&lt;P&gt;Does this mean I've messed up creating a feed?&lt;/P&gt;

&lt;P&gt;Thanks for your time.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 19:00:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248721#M1762</guid>
      <dc:creator>austinparker</dc:creator>
      <dc:date>2016-01-11T19:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248722#M1763</link>
      <description>&lt;P&gt;Austin , &lt;/P&gt;

&lt;P&gt;Make sure the user name ( in this case most likely "admin" judging by your feed name admin,IPWatchlist ) and the password are correct in Splunk and that the User ID has rights set up for the feed in Soltra . &lt;/P&gt;

&lt;P&gt;Additionally can you post any relevant log output  ? Log files are a must when trying to debug . &lt;/P&gt;

&lt;P&gt;Kristofer &lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 19:38:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248722#M1763</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-01-11T19:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248723#M1764</link>
      <description>&lt;P&gt;I would think the user would be the user that the Splunk instance is running under, is it not, this user already has appropriate file level rights?  The user I passed to Soltra should have been a soltra only user.  Perhaps my logic is wrong on this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 20:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248723#M1764</guid>
      <dc:creator>austinparker</dc:creator>
      <dc:date>2016-01-11T20:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248724#M1765</link>
      <description>&lt;P&gt;If ES can pull the Hail a TAXII.com feed directly, why can't it pull FS-ISAC feed too? Why is there a need for Soltra in the middle? &lt;/P&gt;

&lt;P&gt;The only obvious difference between hailataxxi and fs-isac is certificate that is required by fs-isac. Is it possible to implement it straight on ES without Soltra?  &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 16:45:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248724#M1765</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2016-04-07T16:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248725#M1766</link>
      <description>&lt;P&gt;That's a might big feed to pull .. without the Edge box in the middle to set boundaries on dates , times and IOC types you would be pulling quite a bit of data down .. and most of it extraneous . &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 16:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248725#M1766</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-04-07T16:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248726#M1767</link>
      <description>&lt;P&gt;If fact I would recommend the Edge Server between all of your feeds including Hailataxxi , jigsaw, and Threat Actor Lab - gives you a lot of control about what you bring in as a PROD Threat feed&lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 17:19:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248726#M1767</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-04-07T17:19:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248727#M1768</link>
      <description>&lt;P&gt;I agree, FS-ISAC feed it probably not the cleanest, however Soltra does not have more filtering functionality that Splunk does. If Splunk can handle other taxii feeds directly, why would FS-ISAC be different?&lt;/P&gt;

&lt;P&gt;You are pulling the exact same feed from Soltra that you are pulling from FS-ISAC, right? Or is there an ability on Soltra to filter it down to a different feed before it is digested by Splunk? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 17:25:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248727#M1768</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2016-04-07T17:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248728#M1769</link>
      <description>&lt;P&gt;No not necessarily - &lt;/P&gt;

&lt;P&gt;With FS-ISAC you set up your initial feed on their side at analysis.fsisac.com rather than system.default. from there set up an Edge box to pull your clean , "tuned" FS-ISAC feed local or near to your Splunk instance . This allows you to set date parameters for the pull as well - so your not pulling the whole repository back from 2014 - say just the last 6 months . One can also select which IOC types you want to bring into your Splunk environment .&lt;/P&gt;

&lt;P&gt;Additionally on the Edge box that one has set up locally you can add hailataxxi, jigsaw, and Threat Actor as feeds and set parameters for each e.g. only poll the last 24hrs of data starting at a specific date  , only pull this subset of IOCs from each  STIX repository . &lt;/P&gt;

&lt;P&gt;In my opinion much more malleable to point Splunk at feeds that one has control over ( especially not have to download no-applicable IOCs and or ones which are older than 6 months as that's a heck of a lot of data especially if one is searching for IOCs automatically across large data sets  ) &lt;/P&gt;

&lt;P&gt;Just my 2 cents - your mileage my vary &lt;/P&gt;

&lt;P&gt;Kristofer &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 17:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248728#M1769</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-04-07T17:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248729#M1770</link>
      <description>&lt;P&gt;That makes sense. Thanks Kristofer.  &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 18:01:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248729#M1770</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2016-04-07T18:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248730#M1771</link>
      <description>&lt;P&gt;So yes - Soltra Edge 2.8.x allows you to filter down before you pull , parse and store into Mongo / Splunk ... not just the FS-ISCA feeds but all your STIX feeds . &lt;BR /&gt;
I currently pull form 6 different STIX hubs so it is more than useful . &lt;/P&gt;

&lt;P&gt;Kristofer &lt;/P&gt;</description>
      <pubDate>Thu, 07 Apr 2016 18:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248730#M1771</guid>
      <dc:creator>klaxdal</dc:creator>
      <dc:date>2016-04-07T18:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248731#M1772</link>
      <description>&lt;P&gt;I need help in setting up Soltra credentials on Splunk- Where do I give my Soltra's username and password? In post arguments? Is so, what's the syntax? Please help&lt;/P&gt;</description>
      <pubDate>Tue, 16 May 2017 19:29:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248731#M1772</guid>
      <dc:creator>amalkapuram</dc:creator>
      <dc:date>2017-05-16T19:29:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248732#M1773</link>
      <description>&lt;P&gt;Yes, in POST arguments.&lt;BR /&gt;
collection="system.Default" earliest="-90d" taxii_username="user" taxii_password="pass" &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 14:05:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248732#M1773</guid>
      <dc:creator>aliakseidzianis</dc:creator>
      <dc:date>2020-09-29T14:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure an FS-ISAC feed in Splunk App for Enterprise Security 3.3 with a Soltra Edge server?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248733#M1774</link>
      <description>&lt;P&gt;Thanks for your help. I see FSISAC data on Splunk Instance when I ssh into it, the feed got downloaded in ".xml" format. Now when I try to search for that data in Threat Activity or any other place I cant find it. How can I confirm that Splunk is able to parse and read this data?&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2017 22:31:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-to-configure-an-FS-ISAC-feed-in-Splunk-App-for-Enterprise/m-p/248733#M1774</guid>
      <dc:creator>amalkapuram</dc:creator>
      <dc:date>2017-09-13T22:31:16Z</dc:date>
    </item>
  </channel>
</rss>

