<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I stop the &amp;quot;threat list download failed after multiple retries&amp;quot; messages on disabled threat inputs? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273567#M2159</link>
    <description>&lt;P&gt;I also deleted the file and can validate the messages have stopped. Also they seem to have the feed working again.&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2016 20:42:25 GMT</pubDate>
    <dc:creator>splunker288</dc:creator>
    <dc:date>2016-12-22T20:42:25Z</dc:date>
    <item>
      <title>How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273560#M2152</link>
      <description>&lt;P&gt;It looks like the seven  iblocklist feeds included in Splunk Enterprise Security (ES) 4.5.0 are now subscription based and ES can no longer pull them. &lt;/P&gt;

&lt;P&gt;To try and stop the messages, &lt;BR /&gt;
1. I disabled the feeds in Data inputs » Threat Intelligence Downloads&lt;BR /&gt;
2. I modified the Interval to 610000 (once a week)&lt;BR /&gt;
3. Under \local\inputs.conf[configuration_check://confcheck_failed_threat_download], added  files to suppress (SOLNESS-10559 in known issues)&lt;/P&gt;

&lt;P&gt;Every three hours, the messages show up.&lt;/P&gt;

&lt;P&gt;What else do I need to do to stop these messages?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273560#M2152</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2020-09-29T12:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273561#M2153</link>
      <description>&lt;P&gt;I'm having the same issue. I can't get these alerts to stop even after the threat feed is working again.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 15:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273561#M2153</guid>
      <dc:creator>splunker288</dc:creator>
      <dc:date>2016-12-22T15:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273562#M2154</link>
      <description>&lt;P&gt;Show me your exact errors, and I will tell you how to fix them.&lt;/P&gt;

&lt;P&gt;E.G. is it a TAXII feed Error or is it alexa/comprimisedip&lt;/P&gt;

&lt;P&gt;And what version are you running.  &lt;/P&gt;

&lt;P&gt;Okie&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 17:46:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273562#M2154</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2016-12-22T17:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273563#M2155</link>
      <description>&lt;P&gt;I am receiving the following message -&lt;/P&gt;

&lt;P&gt;msg="A threat intelligence download has failed" stanza="emerging_threats_compromised_ip_blocklist" status="threat list download failed after multiple retries"&lt;/P&gt;

&lt;P&gt;ES version is 4.5.0&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:11:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273563#M2155</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2020-09-29T12:11:42Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273564#M2156</link>
      <description>&lt;P&gt;Great, so for this one.  I filed:&lt;BR /&gt;
SOLNESS-11180&lt;BR /&gt;
[PUBLIC] [CUSTOMER] Threat Intelligence: emerging_threats_compromised_ip_blocklist is no longer available for download&lt;BR /&gt;
It seems the vendor has quit publishing this list. (We are awaiting for confirmation if they have disabled for good we will remove from product)&lt;/P&gt;

&lt;P&gt;So please disable the feed.&lt;/P&gt;

&lt;P&gt;Because you are running 4.5.0 you are also hitting SOLNESS-10813, so even after you disable the download, we have an issue.&lt;BR /&gt;
To fix this delete:&lt;BR /&gt;
$SPLUNK_HOME/var/lib/splunk/modinputs/configuration_check/confcheck_failed_threat_download&lt;/P&gt;

&lt;P&gt;And you should be all fixed up.   SOLNESS-10813 was fixed in 4.5.1&lt;/P&gt;

&lt;P&gt;Okie&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 12:11:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273564#M2156</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2020-09-29T12:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273565#M2157</link>
      <description>&lt;P&gt;I'm seeing the exact same error and also running 4.5.0.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 18:52:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273565#M2157</guid>
      <dc:creator>splunker288</dc:creator>
      <dc:date>2016-12-22T18:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273566#M2158</link>
      <description>&lt;P&gt;I removed the file and so far I am no longer getting the messages.  &lt;/P&gt;

&lt;P&gt;Thank you for the help.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 20:34:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273566#M2158</guid>
      <dc:creator>scottrunyon</dc:creator>
      <dc:date>2016-12-22T20:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273567#M2159</link>
      <description>&lt;P&gt;I also deleted the file and can validate the messages have stopped. Also they seem to have the feed working again.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 20:42:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273567#M2159</guid>
      <dc:creator>splunker288</dc:creator>
      <dc:date>2016-12-22T20:42:25Z</dc:date>
    </item>
    <item>
      <title>Re: How do I stop the "threat list download failed after multiple retries" messages on disabled threat inputs?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273568#M2160</link>
      <description>&lt;P&gt;Great news all, sorry for the confusion!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 22:25:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/How-do-I-stop-the-quot-threat-list-download-failed-after/m-p/273568#M2160</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2016-12-22T22:25:49Z</dc:date>
    </item>
  </channel>
</rss>

