<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Maxmind Threat Intelligence Database is not downloading in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419992#M5163</link>
    <description>&lt;P&gt;Anyone know if this has been fixed yet?  &lt;/P&gt;</description>
    <pubDate>Tue, 26 Mar 2019 19:40:36 GMT</pubDate>
    <dc:creator>tommoore</dc:creator>
    <dc:date>2019-03-26T19:40:36Z</dc:date>
    <item>
      <title>Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419987#M5158</link>
      <description>&lt;P&gt;Hi there, I noticed that the URL path for the MaxMind ASN Database has changed on, to another path, and the siem can research for the file.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6426i8D43B5B9AF596F4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6427i52E74005838ED8CC/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;When I tried to put the new path, I realize that the zip file has a folder with two files and it is unreadable for the Splunk&lt;/P&gt;

&lt;P&gt;¿Anyone has the same problem? ¿Is there another way to update the threat intelligence with IP Geolocation?&lt;/P&gt;

&lt;P&gt;Best Regards,&lt;BR /&gt;
Jose León&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 16:45:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419987#M5158</guid>
      <dc:creator>josephliion</dc:creator>
      <dc:date>2019-01-21T16:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419988#M5159</link>
      <description>&lt;P&gt;Where are you using the ASN file?  Splunk ships with GeoLite2-City.mmdb, which is all that you should need to update.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jan 2019 19:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419988#M5159</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-01-21T19:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419989#M5160</link>
      <description>&lt;P&gt;The ASN file is used in ES in the below lookup Gens&lt;/P&gt;

&lt;P&gt;Threat - ASN CIDR Matches - Lookup Gen&lt;BR /&gt;
Threat - ASN IPv6 CIDR Matches - Lookup Gen&lt;BR /&gt;
Threat - ASN String Matches - Lookup Gen&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jan 2019 16:43:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419989#M5160</guid>
      <dc:creator>kaw243</dc:creator>
      <dc:date>2019-01-22T16:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419990#M5161</link>
      <description>&lt;P&gt;Hi Jose, &lt;/P&gt;

&lt;P&gt;This has been identified as an issue to be addressed under  &lt;STRONG&gt;SOLNESS-17731&lt;/STRONG&gt;&lt;BR /&gt;
 - " &lt;EM&gt;Name and location of the MaxMind GeoIP database has changed&lt;/EM&gt; "&lt;/P&gt;

&lt;P&gt;At present others are using the workaround of extracting the downloaded zip folder to a hosted web server or e.g. github repository.&lt;/P&gt;

&lt;P&gt;Hope it helps,&lt;BR /&gt;
Cheers,&lt;BR /&gt;
Matt -  Splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jan 2019 21:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419990#M5161</guid>
      <dc:creator>mdillon_splunk</dc:creator>
      <dc:date>2019-01-26T21:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419991#M5162</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;There are several Splunkbase Apps around this, with one of the latest being the :  ASN Lookup Generator&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3531"&gt;https://splunkbase.splunk.com/app/3531&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 06:02:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419991#M5162</guid>
      <dc:creator>mdillon_splunk</dc:creator>
      <dc:date>2019-02-06T06:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419992#M5163</link>
      <description>&lt;P&gt;Anyone know if this has been fixed yet?  &lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2019 19:40:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/419992#M5163</guid>
      <dc:creator>tommoore</dc:creator>
      <dc:date>2019-03-26T19:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/511229#M9075</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/148769"&gt;@mdillon_splunk&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is now a requirement that we and other users first obtain a free license key from MaxMind (&lt;A href="https://blog.maxmind.com/2019/12/18/significant-changes-to-accessing-and-using-geolite2-databases/" target="_blank"&gt;https://blog.maxmind.com/2019/12/18/significant-changes-to-accessing-and-using-geolite2-databases/&lt;/A&gt;) and update the link to take this into account such that the URL becomes "&lt;A href="https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-ASN-CSV&amp;amp;license_key=INSERT_LICENSE_KEY_HERE&amp;amp;suffix=zip" target="_self"&gt;https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-ASN-CSV&amp;amp;license_key=&lt;EM&gt;&lt;STRONG&gt;INSERT_LICENSE_KEY_HERE&lt;/STRONG&gt;&lt;/EM&gt;&amp;amp;suffix=zip&lt;/A&gt;".&lt;/P&gt;&lt;P&gt;The reason I'm raising this after quite some time since the last post on this thread is that I'm wondering whether "&lt;STRONG&gt;SOLNESS-17731&lt;/STRONG&gt;" is also planning to take into account that the backend Python code that Splunk uses for this functionality (called "threatlist.py" &amp;amp; "protocols.py") seems to currently be unable to process archives which have multiple files within, as the screenshot below from my experimentation shows:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="MultiFileArchiveProblem.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9891i7E7D3B8D27FFAB45/image-size/large?v=v2&amp;amp;px=999" role="button" title="MultiFileArchiveProblem.png" alt="MultiFileArchiveProblem.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem here is that MaxMind currently doesn't provide these files except as part of a ZIP or TAR.GZ archive with the following multi-file structure:&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Folder: GeoLite2-ASN-CSV_20200728&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;File underneath: GeoLite2-ASN-Blocks-IPv4.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;File underneath: COPYRIGHT.txt&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;File underneath: GeoLite2-ASN-Blocks-IPv6.csv&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;File underneath: LICENSE.txt&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Thus, it would be ideal if we could somehow specify a configuration parameter when setting up the input like "File location: GeoLite2-ASN-CSV_YYYYmmdd/GeoLite2-ASN-Blocks-IPv4.csv" so that we can select which file Splunk will parse out of the archive.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a use case which relies on these CIDR IP &amp;lt;&amp;gt; ASN mappings so it would be great to get an update on whether something like the above has been considered as part of "&lt;STRONG&gt;SOLNESS-17731&lt;/STRONG&gt;"; also could you please let me know if this should rather be raised as a Splunk Idea instead.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks !&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 20:59:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/511229#M9075</guid>
      <dc:creator>rragazan</dc:creator>
      <dc:date>2020-07-27T20:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Maxmind Threat Intelligence Database is not downloading</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/518001#M9231</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224153"&gt;@rragazan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue should now be addressed with Enterprise Security 6.2.0&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/ES/6.2.0/RN/FixedIssues" target="_blank"&gt;https://docs.splunk.com/Documentation/ES/6.2.0/RN/FixedIssues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;SOLNESS-22110&amp;nbsp; &amp;nbsp;- Threat Intelligence: Maxmind ASN database can no longer be consumed&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2020 01:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Maxmind-Threat-Intelligence-Database-is-not-downloading/m-p/518001#M9231</guid>
      <dc:creator>mdillon_splunk</dc:creator>
      <dc:date>2020-09-05T01:15:33Z</dc:date>
    </item>
  </channel>
</rss>

