<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES - Threat Intelligence TAXII feed not Working in Splunk Cloud in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/486518#M8022</link>
    <description>&lt;P&gt;Hey Guys,&lt;/P&gt;
&lt;P&gt;We are in a Splunk Cloud environment with ES, and we have added our own TAXII feed as well as some open source TAXII feeds and we can see that they start "polling" but we never see them download any collection sets or fail in the event logs so it doesn't appear to be working.&lt;/P&gt;
&lt;P&gt;Has anyone else configured this in Splunk Cloud and if so do you know if there is something else we need to enable for our TAXII feeds to work?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Sun, 07 Jun 2020 16:24:47 GMT</pubDate>
    <dc:creator>sheenay</dc:creator>
    <dc:date>2020-06-07T16:24:47Z</dc:date>
    <item>
      <title>Splunk ES - Threat Intelligence TAXII feed not Working in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/486518#M8022</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;
&lt;P&gt;We are in a Splunk Cloud environment with ES, and we have added our own TAXII feed as well as some open source TAXII feeds and we can see that they start "polling" but we never see them download any collection sets or fail in the event logs so it doesn't appear to be working.&lt;/P&gt;
&lt;P&gt;Has anyone else configured this in Splunk Cloud and if so do you know if there is something else we need to enable for our TAXII feeds to work?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 16:24:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/486518#M8022</guid>
      <dc:creator>sheenay</dc:creator>
      <dc:date>2020-06-07T16:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES - Threat Intelligence TAXII feed not Working in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/524584#M9383</link>
      <description>&lt;P&gt;I'm currently facing the same issue, have you resolved this already? Would you mind sharing the solution if ever? Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Oct 2020 11:02:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/524584#M9383</guid>
      <dc:creator>dantimola</dc:creator>
      <dc:date>2020-10-14T11:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES - Threat Intelligence TAXII feed not Working in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/525410#M9392</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not a solution, but I noticed this while trying to integrate taxii feed from MITRE:&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;taxii2client&lt;/STRONG&gt;&amp;nbsp;in Splunk ES tries to download by default with the latest taxii protocol version (v21?), and MITRE supported only&amp;nbsp;&lt;STRONG&gt;v20&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;Tried to download from a Python script using &lt;STRONG&gt;v20&lt;/STRONG&gt;&amp;nbsp;and worked.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2020 16:04:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/525410#M9392</guid>
      <dc:creator>Laszlo_K</dc:creator>
      <dc:date>2020-10-19T16:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES - Threat Intelligence TAXII feed not Working in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/573737#M10439</link>
      <description>&lt;P&gt;Not intending to drag up an old topic, but I'm interested in knowing what "taxii2client" is referencing?&lt;/P&gt;&lt;P&gt;It's my understanding that the latest versions of Splunk ES do not natively support TAXII v2.&lt;/P&gt;&lt;P&gt;Is&amp;nbsp;this in reference to a custom install of taxii2client from OASIS Open onto a Splunk ES instance, and somehow configuring it to work with feed ingestion to the Intelligence framework/collections?&lt;/P&gt;&lt;P&gt;I've recently been trying to identify the best supported solution for STIX 2.1 feeds, which require TAXII 2 communications, into Splunk ES, so I'm curious about the points made in this discussion and what options have been working.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 03:53:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Threat-Intelligence-TAXII-feed-not-Working-in-Splunk/m-p/573737#M10439</guid>
      <dc:creator>Scentri</dc:creator>
      <dc:date>2021-11-05T03:53:12Z</dc:date>
    </item>
  </channel>
</rss>

