<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk App for Enterprise Security: Why am I getting error messages &amp;quot;msg=&amp;quot;A threat intelligence download has failed&amp;quot;...status=&amp;quot;threat list could not be written to disk&amp;quot;&amp;quot;? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171365#M757</link>
    <description>&lt;P&gt;The search head and the indexer had access to internet but I Still get thé same message errors. &lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2015 17:42:54 GMT</pubDate>
    <dc:creator>Afef</dc:creator>
    <dc:date>2015-06-30T17:42:54Z</dc:date>
    <item>
      <title>Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171355#M747</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I installed the Splunk App for Enterprise Security  (simple deployment). I get many error messages : &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites" status="threat list could not be written to disk"

msg="A threat intelligence download has failed" stanza="mozilla_public_suffix_list" status="threat list could not be written to disk"
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Could someone help me  please ?&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 07:12:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171355#M747</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-24T07:12:55Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171356#M748</link>
      <description>&lt;P&gt;I believe this is a known bug.&lt;/P&gt;

&lt;P&gt;All you should have to do is find this script - &lt;CODE&gt;confcheck_failed_threat_download.py&lt;/CODE&gt; and change this line: &lt;BR /&gt;
 &lt;CODE&gt;job = splunk.search.dispatch(srch, sessionKey=session_key, &lt;BR /&gt;
 earliest=earliest)&lt;/CODE&gt;&lt;BR /&gt;
 to this line: &lt;BR /&gt;
&lt;CODE&gt;job = splunk.search.dispatch(srch, sessionKey=session_key, &lt;BR /&gt;
earliestTime=earliest)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;@bosburn_splunk, correct me if I'm wrong.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 11:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171356#M748</guid>
      <dc:creator>alacercogitatus</dc:creator>
      <dc:date>2015-06-24T11:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171357#M749</link>
      <description>&lt;P&gt;That fix was for a different error:&lt;BR /&gt;
"A threat intelligence download has failed" stanza=“stanza_name" status="threat list download failed after multiple retries"&lt;/P&gt;

&lt;P&gt;This one sounds like a permissions issue.  Are you running Windows?  Have you checked the permissions on the destination file that it's trying to overwrite?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 12:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171357#M749</guid>
      <dc:creator>bosburn_splunk</dc:creator>
      <dc:date>2015-06-24T12:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171358#M750</link>
      <description>&lt;P&gt;Yes i'M running splunk on Windows.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2015 20:17:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171358#M750</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-24T20:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171359#M751</link>
      <description>&lt;P&gt;How could find the destination file ? there was no information about it !&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2015 22:53:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171359#M751</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-25T22:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171360#M752</link>
      <description>&lt;P&gt;Hi, does the host has internet access ? Through a proxy ?&lt;BR /&gt;
Does the download script runs manualy ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 07:59:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171360#M752</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2015-06-26T07:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171361#M753</link>
      <description>&lt;P&gt;Hi, no the host didn't have internet access. &lt;BR /&gt;
Which script ?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 08:03:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171361#M753</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-26T08:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171362#M754</link>
      <description>&lt;P&gt;If the search head does not have internet access, even through a proxy, ES will be unable to download the threat lists. You don't need to look further !&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jun 2015 09:20:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171362#M754</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2015-06-26T09:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171363#M755</link>
      <description>&lt;P&gt;Now, the search head has internet access. But i still have the same errors !&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 07:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171363#M755</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-30T07:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171364#M756</link>
      <description>&lt;P&gt;Afef, the Threat list are downloaded from internet !&lt;BR /&gt;
If you do not have internet access, just disable the threat lists, or copy them locally and modify them.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 17:16:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171364#M756</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2015-06-30T17:16:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171365#M757</link>
      <description>&lt;P&gt;The search head and the indexer had access to internet but I Still get thé same message errors. &lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 17:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171365#M757</guid>
      <dc:creator>Afef</dc:creator>
      <dc:date>2015-06-30T17:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171366#M758</link>
      <description>&lt;P&gt;Only the SH needs Internet access.&lt;BR /&gt;
And check if the following script is running :&lt;BR /&gt;
&lt;EM&gt;/opt/splunk/bin/splunk cmd python ./threatlist.py&lt;/EM&gt;&lt;BR /&gt;
(you may add a -v after python if needed).&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2015 23:34:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171366#M758</guid>
      <dc:creator>mdessus_splunk</dc:creator>
      <dc:date>2015-06-30T23:34:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171367#M759</link>
      <description>&lt;P&gt;Afef, &lt;/P&gt;

&lt;P&gt;If you're running 6.2.3, here is the location of the threatlists. I just found mine and the folder was indeed read only. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;C:\Program Files\Splunk\etc\apps\SA-ThreatIntelligence\local\data\threat_intel
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 08 Jul 2015 20:42:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171367#M759</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2015-07-08T20:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171368#M760</link>
      <description>&lt;P&gt;I just fixed the same error. My ES Windows deployment, the folder &lt;BR /&gt;
&lt;CODE&gt;C:\Program Files\Splunk\etc\apps\SA-ThreatIntelligence\local\data\threat_intel&lt;/CODE&gt;&lt;BR /&gt;
was set to ready-only. Quick change of the settings and everything is running smoother. &lt;/P&gt;

&lt;P&gt;Good luck!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2015 18:14:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171368#M760</guid>
      <dc:creator>serwin</dc:creator>
      <dc:date>2015-07-10T18:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171369#M761</link>
      <description>&lt;P&gt;Still No luck , after changing the Permissions.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Sep 2015 04:32:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171369#M761</guid>
      <dc:creator>neelamssantosh</dc:creator>
      <dc:date>2015-09-14T04:32:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171370#M762</link>
      <description>&lt;P&gt;Where do i find this file in the linux system? i tried the /Splunk_home/etc/apps but couldn't find this          "SA-ThreatIntelligence" app.. &lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2016 17:20:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171370#M762</guid>
      <dc:creator>japala</dc:creator>
      <dc:date>2016-09-16T17:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171371#M763</link>
      <description>&lt;P&gt;Well I did find the proper location under $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data but the permissions seem fine. Any other thoughts?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Oct 2016 16:09:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171371#M763</guid>
      <dc:creator>tryan65</dc:creator>
      <dc:date>2016-10-31T16:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171372#M764</link>
      <description>&lt;P&gt;Hi our ES is 4.5.1. So I checked the confcheck_failed_threat_download.py. Looks like the line been updated already. Possible the bug been fixed? However, I still getting some error. Most of the stanza been downloaded successfully. Only emerging_threats_ip_blocklist AND iblocklist_tor download failed.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171372#M764</guid>
      <dc:creator>season88481</dc:creator>
      <dc:date>2020-09-29T13:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171373#M765</link>
      <description>&lt;P&gt;Is it:&lt;BR /&gt;
earliest_time=earliest&lt;BR /&gt;
OR &lt;BR /&gt;
earliestTime=earliest&lt;BR /&gt;
For this fix? There is a different post with that variation.&lt;BR /&gt;
Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jun 2017 00:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171373#M765</guid>
      <dc:creator>mrgibbon</dc:creator>
      <dc:date>2017-06-30T00:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171374#M766</link>
      <description>&lt;P&gt;This has been happening to me for about 2 weeks. I've tried or checked everything I could find on Splunk answers but still get the error.  The file permissions are correct and the file is actually downloaded but we still get the error. I've disabled the download but still get the error. I've checked the python script and it already has the updated line.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;A threat intelligence download has failed. stanza="malware_domains" host="servername" status="threat list download failed after multiple retries"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;we currently run Splunk on a windows 2012 r2 server, Splunk 6.6.0 and ES App Version 4.7.1 App Build 17&lt;/P&gt;</description>
      <pubDate>Mon, 18 Sep 2017 16:24:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-App-for-Enterprise-Security-Why-am-I-getting-error/m-p/171374#M766</guid>
      <dc:creator>jamesbrock</dc:creator>
      <dc:date>2017-09-18T16:24:40Z</dc:date>
    </item>
  </channel>
</rss>

