<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [Bug] Download threat intelligence feed ignoring Timeout setting in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/468222#M7065</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Working on a threatq list which takes more than 1min to be generated, I was always looping in splunk with :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;status="threat list download failed after multiple retries" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I have discovered that in the &lt;CODE&gt;Intelligence Download Settings&lt;/CODE&gt;,  the field &lt;CODE&gt;Timeout&lt;/CODE&gt; is a lie, as it is not used for real in the code behind.&lt;BR /&gt;
In the script &lt;CODE&gt;/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/threatlist.py&lt;/CODE&gt; the value is set to a variable &lt;CODE&gt;timeout&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;self.DEFAULT_TIMEOUT_INTERVAL = 30
(......)
IntegerField("timeout", "Timeout interval", "Time before regarding a download attempt as failed, in seconds.  [Defaults to {0}]".format(self.DEFAULT_TIMEOUT_INTERVAL), required_on_create=True, required_on_edit=True),
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But after the call of &lt;CODE&gt;/opt/splunk/etc/apps/SA-Utils/lib/SolnCommon/protocols.py&lt;/CODE&gt; we have :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_timeout = 30  # The timeout for queries conducted by this handler.
(......)
def set_options(self, *args, **kwargs):

    valid_keys = ['app', 'debug', 'owner', 'proxy_port',
                  'proxy_server', 'proxy_user', 'proxy_password',
                  'site_user', 'site_password', 'user_agent']
(......)
    try:
        response = urllib2.urlopen(request, timeout=self._timeout)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So at the end the http timeout is always to &lt;STRONG&gt;30s&lt;/STRONG&gt; max whatever you will set&lt;/P&gt;

&lt;P&gt;¯\&lt;EM&gt;(ツ)&lt;/EM&gt;/¯&lt;/P&gt;</description>
    <pubDate>Thu, 19 Dec 2019 14:23:32 GMT</pubDate>
    <dc:creator>FloSwiip</dc:creator>
    <dc:date>2019-12-19T14:23:32Z</dc:date>
    <item>
      <title>[Bug] Download threat intelligence feed ignoring Timeout setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/468222#M7065</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Working on a threatq list which takes more than 1min to be generated, I was always looping in splunk with :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;status="threat list download failed after multiple retries" 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;And I have discovered that in the &lt;CODE&gt;Intelligence Download Settings&lt;/CODE&gt;,  the field &lt;CODE&gt;Timeout&lt;/CODE&gt; is a lie, as it is not used for real in the code behind.&lt;BR /&gt;
In the script &lt;CODE&gt;/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/threatlist.py&lt;/CODE&gt; the value is set to a variable &lt;CODE&gt;timeout&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;self.DEFAULT_TIMEOUT_INTERVAL = 30
(......)
IntegerField("timeout", "Timeout interval", "Time before regarding a download attempt as failed, in seconds.  [Defaults to {0}]".format(self.DEFAULT_TIMEOUT_INTERVAL), required_on_create=True, required_on_edit=True),
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But after the call of &lt;CODE&gt;/opt/splunk/etc/apps/SA-Utils/lib/SolnCommon/protocols.py&lt;/CODE&gt; we have :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;_timeout = 30  # The timeout for queries conducted by this handler.
(......)
def set_options(self, *args, **kwargs):

    valid_keys = ['app', 'debug', 'owner', 'proxy_port',
                  'proxy_server', 'proxy_user', 'proxy_password',
                  'site_user', 'site_password', 'user_agent']
(......)
    try:
        response = urllib2.urlopen(request, timeout=self._timeout)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So at the end the http timeout is always to &lt;STRONG&gt;30s&lt;/STRONG&gt; max whatever you will set&lt;/P&gt;

&lt;P&gt;¯\&lt;EM&gt;(ツ)&lt;/EM&gt;/¯&lt;/P&gt;</description>
      <pubDate>Thu, 19 Dec 2019 14:23:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/468222#M7065</guid>
      <dc:creator>FloSwiip</dc:creator>
      <dc:date>2019-12-19T14:23:32Z</dc:date>
    </item>
    <item>
      <title>Re: [Bug] Download threat intelligence feed ignoring Timeout setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/468223#M7066</link>
      <description>&lt;P&gt;I post my crap and dirty solution in case...&lt;/P&gt;

&lt;P&gt;Edit &lt;CODE&gt;/opt/splunk/etc/apps/SA-ThreatIntelligence/bin/threatlist.py&lt;/CODE&gt; look for the part :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        handler = handler_cls(self._logger, self._input_config.session_key, **handler_args)
        temp_checkpoint_filehandle = None
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and add just after it&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        handler._timeout = handler_args.get('timeout')
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 19 Dec 2019 14:26:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/468223#M7066</guid>
      <dc:creator>FloSwiip</dc:creator>
      <dc:date>2019-12-19T14:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: [Bug] Download threat intelligence feed ignoring Timeout setting</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/579098#M10499</link>
      <description>&lt;P&gt;The bug is still there.&lt;/P&gt;&lt;P&gt;As the code was a bit reworked now the solution is to :&lt;BR /&gt;&lt;BR /&gt;Edit /opt/splunk/etc/apps/SA-ThreatIntelligence/bin/threatlist.py&lt;BR /&gt;and add at line 497&lt;BR /&gt;handler._timeout = handler_args.get('timeout')&lt;/P&gt;</description>
      <pubDate>Wed, 22 Dec 2021 10:24:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Bug-Download-threat-intelligence-feed-ignoring-Timeout-setting/m-p/579098#M10499</guid>
      <dc:creator>FloSwiip</dc:creator>
      <dc:date>2021-12-22T10:24:39Z</dc:date>
    </item>
  </channel>
</rss>

