<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Add lookup based source for ES in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343511#M3253</link>
    <description>&lt;P&gt;Under threat intelligence management it looks like this&lt;/P&gt;

&lt;P&gt;Name                             Directory&lt;BR /&gt;
da_ess_threat_default   $SPLUNK_HOME/etc/apps/DA-ESS-ThreatIntelligence/default/data/threat_intel&lt;BR /&gt;
da_ess_threat_local $SPLUNK_HOME/etc/apps/DA-ESS-ThreatIntelligence/local/data/threat_intel&lt;BR /&gt;
local_lookups             ignored&lt;BR /&gt;
sa_threat_local $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data/threat_intel&lt;/P&gt;

&lt;P&gt;The lookups in question are currently in the app/lookups dir&lt;/P&gt;

&lt;P&gt;The events that I am trying to get picked up into the "threat_activity" index are watchguard logs like this:&lt;BR /&gt;
    Apr 10 13:32:11 &lt;STRONG&gt;&lt;EM&gt;-FB-02 *&lt;/EM&gt;&lt;/STRONG&gt;1016F5DC (2018-04-10T03:32:11) http-proxy[2256]: msg_id="1AFF-0024" Allow 2-Inside 5-Uecomm10 tcp 172.&lt;EM&gt;.&lt;/EM&gt;.* 212.&lt;EM&gt;.&lt;/EM&gt;.* 51153 80 msg="HTTP request" proxy_act="HTTP-Client.3" op="GET" dstname="api.wipmania.com" arg="/jsonp?callback=jQuery191009073215578267857_1523331069485&amp;amp;_=1523331069486" sent_bytes="442" rcvd_bytes="602" elapsed_time="0.657724 sec(s)" app_id="128" app_cat_id="13" app_name="Microsoft Edge" app_cat_name="Web services" reputation="1" reason="262189" action="allow"  (HTTP-proxy-00)&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 19:12:21 GMT</pubDate>
    <dc:creator>proylea</dc:creator>
    <dc:date>2020-09-29T19:12:21Z</dc:date>
    <item>
      <title>Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343506#M3248</link>
      <description>&lt;P&gt;Looking over the clients configuration for adding a lookup based source for Enterprise Security Threat Intelligence, it appears to be configured correctly.&lt;BR /&gt;
However I still see zero events in the dashboard even though a search returns the test values for threats that have been ingested.&lt;BR /&gt;
The source lookup for IP's containing the Crowdstrike IOC's has global permissions and contains 3 fields only&lt;BR /&gt;
description, ip, weight&lt;BR /&gt;
The document followed for this configuration is here &lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/3.3.0/Install/Configureblocklists#Add_a_file_based_threat_source"&gt;http://docs.splunk.com/Documentation/ES/3.3.0/Install/Configureblocklists#Add_a_file_based_threat_source&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4786i22F10BE6287EF44B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Continuing to look for the source of the problem but would appreciate any input from our awesome Splunk crew.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 05:23:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343506#M3248</guid>
      <dc:creator>proylea</dc:creator>
      <dc:date>2018-04-20T05:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343507#M3249</link>
      <description>&lt;P&gt;Hi proylea,&lt;/P&gt;

&lt;P&gt;Looking at your dashboard, have you checked that your tokens are well configured in your search?&lt;BR /&gt;
- For the four filters&lt;BR /&gt;
- And especially for the 'Threat match value', do you have '*' value by default?&lt;/P&gt;

&lt;P&gt;Sometimes things are simple, I hope this would help&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 11:48:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343507#M3249</guid>
      <dc:creator>rom1btn</dc:creator>
      <dc:date>2018-04-20T11:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343508#M3250</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;first, what version of ES are you using: 3.3 is an old release and you should look at the relevant doc version like this one: &lt;A href="http://docs.splunk.com/Documentation/ES/5.0.0/Admin/UploadCSVthreatfile"&gt;http://docs.splunk.com/Documentation/ES/5.0.0/Admin/UploadCSVthreatfile&lt;/A&gt; . That said, the file format should be the same.&lt;BR /&gt;
You should check if your threat list is correctly uploaded, either by looking in the Threat artifacts dashboards, either using this command: &lt;CODE&gt;| inputlookup threatintel_by_cidr&lt;/CODE&gt; &lt;/P&gt;

&lt;P&gt;Next, validate that your src field from your event is correctly mapped to the CIM, and is used by ES. What kind of data do you want to match to ?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 12:03:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343508#M3250</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2018-04-20T12:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343509#M3251</link>
      <description>&lt;P&gt;The lookup is local_ip_intel and it contains IP addresses and descriptions&lt;BR /&gt;
In the Threat intelligence audit dashboard the download status is blank.&lt;/P&gt;

&lt;P&gt;The source field is correctly mapped to the CIM &lt;/P&gt;

&lt;P&gt;The threat list "local_ip_intel" does not appear when I execute &lt;BR /&gt;
| inputlookup threatintel_by_cidr&lt;/P&gt;

&lt;P&gt;So I assume I need the content from the new lookup "local_ip_intel" to end up in the "threatintel_by_cdr" lookup. and if so how is it supposed to get there?&lt;/P&gt;

&lt;P&gt;I notice when you upload a new threat list it places it in the local/data/threat_intel dir in the app.&lt;BR /&gt;
Are the threat lists supposed to live there? these ones are currently in the lookup dir&lt;BR /&gt;
What is the standard for these threat lists, the documentation is not that clear.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:11:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343509#M3251</guid>
      <dc:creator>proylea</dc:creator>
      <dc:date>2020-09-29T19:11:34Z</dc:date>
    </item>
    <item>
      <title>Re: Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343510#M3252</link>
      <description>&lt;P&gt;Just to be sure, you configured the local input in ES here: &lt;EM&gt;Data inputs » Threat Intelligence Management » local_lookups&lt;/EM&gt;   ?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 07:00:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343510#M3252</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2018-04-23T07:00:04Z</dc:date>
    </item>
    <item>
      <title>Re: Add lookup based source for ES</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343511#M3253</link>
      <description>&lt;P&gt;Under threat intelligence management it looks like this&lt;/P&gt;

&lt;P&gt;Name                             Directory&lt;BR /&gt;
da_ess_threat_default   $SPLUNK_HOME/etc/apps/DA-ESS-ThreatIntelligence/default/data/threat_intel&lt;BR /&gt;
da_ess_threat_local $SPLUNK_HOME/etc/apps/DA-ESS-ThreatIntelligence/local/data/threat_intel&lt;BR /&gt;
local_lookups             ignored&lt;BR /&gt;
sa_threat_local $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data/threat_intel&lt;/P&gt;

&lt;P&gt;The lookups in question are currently in the app/lookups dir&lt;/P&gt;

&lt;P&gt;The events that I am trying to get picked up into the "threat_activity" index are watchguard logs like this:&lt;BR /&gt;
    Apr 10 13:32:11 &lt;STRONG&gt;&lt;EM&gt;-FB-02 *&lt;/EM&gt;&lt;/STRONG&gt;1016F5DC (2018-04-10T03:32:11) http-proxy[2256]: msg_id="1AFF-0024" Allow 2-Inside 5-Uecomm10 tcp 172.&lt;EM&gt;.&lt;/EM&gt;.* 212.&lt;EM&gt;.&lt;/EM&gt;.* 51153 80 msg="HTTP request" proxy_act="HTTP-Client.3" op="GET" dstname="api.wipmania.com" arg="/jsonp?callback=jQuery191009073215578267857_1523331069485&amp;amp;_=1523331069486" sent_bytes="442" rcvd_bytes="602" elapsed_time="0.657724 sec(s)" app_id="128" app_cat_id="13" app_name="Microsoft Edge" app_cat_name="Web services" reputation="1" reason="262189" action="allow"  (HTTP-proxy-00)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 19:12:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Add-lookup-based-source-for-ES/m-p/343511#M3253</guid>
      <dc:creator>proylea</dc:creator>
      <dc:date>2020-09-29T19:12:21Z</dc:date>
    </item>
  </channel>
</rss>

