<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Enterprise Security: Why am I getting this error message &amp;quot;msg=&amp;quot;A threat intelligence download has failed&amp;quot; stanza=&amp;quot;alexa_top_one_million_sites&amp;quot;&amp;quot;? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344051#M3267</link>
    <description>&lt;P&gt;Hmm, this indicates you are a cloud customer.  If that is the case email me your info jwelch @ splunk dot com.&lt;/P&gt;

&lt;P&gt;I will take a look for you.&lt;/P&gt;

&lt;P&gt;Otherwise, if I am missing something here, we log the success or failure of a download in the threatlist.log in /opt/splunk/var/log/splunk&lt;/P&gt;

&lt;P&gt;index=_internal source =*threatlist.log alexa&lt;/P&gt;

&lt;P&gt;This could be related to a previous failure and now it is successful, and you are hitting the bug I was talking about, which I did not think affected 4.2.0&lt;/P&gt;

&lt;P&gt;Or it really is failing and I need to see why from the backend.&lt;/P&gt;

&lt;P&gt;If you are not a cloud customer you could try this from your SH&lt;/P&gt;

&lt;P&gt;wget &lt;A href="https://s3.amazonaws.com/alexa-static/top-1m.csv.zip"&gt;https://s3.amazonaws.com/alexa-static/top-1m.csv.zip&lt;/A&gt;? to determine if you have success.&lt;/P&gt;

&lt;P&gt;Let me know here or via email how I can help&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2017 13:46:43 GMT</pubDate>
    <dc:creator>jwelch_splunk</dc:creator>
    <dc:date>2017-03-10T13:46:43Z</dc:date>
    <item>
      <title>Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344044#M3260</link>
      <description>&lt;P&gt;Splunk Enterprise Security: why am I getting this error message?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites" status="threat list download failed after multiple retries"
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 09 Mar 2017 14:41:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344044#M3260</guid>
      <dc:creator>emmanuelpeter</dc:creator>
      <dc:date>2017-03-09T14:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344045#M3261</link>
      <description>&lt;P&gt;Can you access the URL:  &lt;A href="https://s3.amazonaws.com/alexa-static/top-1m.csv.zip"&gt;https://s3.amazonaws.com/alexa-static/top-1m.csv.zip&lt;/A&gt;?  This is where the Alexa Top Million is hosted.  Personally, I can, so I know they haven't shut down the Alext top million (like happened a few months back and presumably will happen again).  It's possible that your Splunk ES Search Head can't access that URL itself, blocked by a content filter or web proxy in your network somewhere.  If you don't use the Alexa Top Million, you could just disable the input.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2017 17:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344045#M3261</guid>
      <dc:creator>mparks11</dc:creator>
      <dc:date>2017-03-09T17:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344046#M3262</link>
      <description>&lt;P&gt;You could also be hitting a bug.&lt;BR /&gt;
What version of ES are you running?  &lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 05:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344046#M3262</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2017-03-10T05:07:41Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344047#M3263</link>
      <description>&lt;P&gt;I'm currently running Splunk Version 6.4.1.2&lt;BR /&gt;
what sort of bug could that be?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 10:48:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344047#M3263</guid>
      <dc:creator>emmanuelpeter</dc:creator>
      <dc:date>2017-03-10T10:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344048#M3264</link>
      <description>&lt;P&gt;I can access the CSV.Zip, but how can I check to see if my search head can access it. Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 10:53:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344048#M3264</guid>
      <dc:creator>emmanuelpeter</dc:creator>
      <dc:date>2017-03-10T10:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344049#M3265</link>
      <description>&lt;P&gt;What version of ES are you running&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 11:50:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344049#M3265</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2017-03-10T11:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344050#M3266</link>
      <description>&lt;P&gt;currently is 4.2.0&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 12:21:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344050#M3266</guid>
      <dc:creator>emmanuelpeter</dc:creator>
      <dc:date>2017-03-10T12:21:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344051#M3267</link>
      <description>&lt;P&gt;Hmm, this indicates you are a cloud customer.  If that is the case email me your info jwelch @ splunk dot com.&lt;/P&gt;

&lt;P&gt;I will take a look for you.&lt;/P&gt;

&lt;P&gt;Otherwise, if I am missing something here, we log the success or failure of a download in the threatlist.log in /opt/splunk/var/log/splunk&lt;/P&gt;

&lt;P&gt;index=_internal source =*threatlist.log alexa&lt;/P&gt;

&lt;P&gt;This could be related to a previous failure and now it is successful, and you are hitting the bug I was talking about, which I did not think affected 4.2.0&lt;/P&gt;

&lt;P&gt;Or it really is failing and I need to see why from the backend.&lt;/P&gt;

&lt;P&gt;If you are not a cloud customer you could try this from your SH&lt;/P&gt;

&lt;P&gt;wget &lt;A href="https://s3.amazonaws.com/alexa-static/top-1m.csv.zip"&gt;https://s3.amazonaws.com/alexa-static/top-1m.csv.zip&lt;/A&gt;? to determine if you have success.&lt;/P&gt;

&lt;P&gt;Let me know here or via email how I can help&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 13:46:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344051#M3267</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2017-03-10T13:46:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344052#M3268</link>
      <description>&lt;P&gt;I've dropped you an email. please do let me know if you receive it.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 15:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344052#M3268</guid>
      <dc:creator>emmanuelpeter</dc:creator>
      <dc:date>2017-03-10T15:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344053#M3269</link>
      <description>&lt;P&gt;Looks like jwelch beat me to the punch!  &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;wget &lt;A href="https://s3.amazonaws.com/alexa-static/top-1m.csv.zip" target="test_blank"&gt;https://s3.amazonaws.com/alexa-static/top-1m.csv.zip&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 10 Mar 2017 15:46:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344053#M3269</guid>
      <dc:creator>mparks11</dc:creator>
      <dc:date>2017-03-10T15:46:40Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344054#M3270</link>
      <description>&lt;P&gt;We ended up working this issue from a support perspective, and this was related to specific configs within the customers ENV.  If customer wishes to share our findings he can note that here.&lt;/P&gt;

&lt;P&gt;Having said that under normal circumstances, using wget to validate connectivity from SH to source is a good first start to understand why the download is failing.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2017 16:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344054#M3270</guid>
      <dc:creator>jwelch_splunk</dc:creator>
      <dc:date>2017-03-10T16:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Enterprise Security: Why am I getting this error message "msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344055#M3271</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/606997/a-threat-intelligence-download-has-failedstatusthr-1.html?childToView=608146#answer-608146"&gt;https://answers.splunk.com/answers/606997/a-threat-intelligence-download-has-failedstatusthr-1.html?childToView=608146#answer-608146&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2018 07:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-Enterprise-Security-Why-am-I-getting-this-error-message/m-p/344055#M3271</guid>
      <dc:creator>risgupta</dc:creator>
      <dc:date>2018-01-03T07:50:20Z</dc:date>
    </item>
  </channel>
</rss>

