<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic TAXII files being downloaded but not processed by Enterprise Security in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/TAXII-files-being-downloaded-but-not-processed-by-Enterprise/m-p/564465#M196635</link>
    <description>&lt;P&gt;Hi Splunkers.&lt;/P&gt;&lt;P&gt;We are having an issue whereby a TAXII feed has stopped being incorporated into the Enterprise Security Threat Intelligence module.&lt;/P&gt;&lt;P&gt;The feed has been working o.k. (i.e. downloading &lt;EM&gt;and&lt;/EM&gt; importing indicators) for some time but in recent times only the download is working.&lt;/P&gt;&lt;P&gt;- Threat Intelligence Audit in ES the download shows no errors (exit_status of 0)&lt;BR /&gt;- We can see the downloaded .xml file with TAXII indicators in the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;SA-ThreatIntelligence/local/data/threat_intel&lt;/STRONG&gt; directory.&lt;BR /&gt;- threatlist.log also shows a successful download&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see anything specific in the logs showing an issue processing the download files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In Security Intelligence --&amp;gt; Threat Intelligence --&amp;gt; Threat Artifacts we see where earlier files.&lt;/P&gt;&lt;P&gt;Any other suggestions for where to look to diagnose/resolve this issue.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Tue, 24 Aug 2021 05:04:22 GMT</pubDate>
    <dc:creator>torowa</dc:creator>
    <dc:date>2021-08-24T05:04:22Z</dc:date>
    <item>
      <title>TAXII files being downloaded but not processed by Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-Search/TAXII-files-being-downloaded-but-not-processed-by-Enterprise/m-p/564465#M196635</link>
      <description>&lt;P&gt;Hi Splunkers.&lt;/P&gt;&lt;P&gt;We are having an issue whereby a TAXII feed has stopped being incorporated into the Enterprise Security Threat Intelligence module.&lt;/P&gt;&lt;P&gt;The feed has been working o.k. (i.e. downloading &lt;EM&gt;and&lt;/EM&gt; importing indicators) for some time but in recent times only the download is working.&lt;/P&gt;&lt;P&gt;- Threat Intelligence Audit in ES the download shows no errors (exit_status of 0)&lt;BR /&gt;- We can see the downloaded .xml file with TAXII indicators in the&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;SA-ThreatIntelligence/local/data/threat_intel&lt;/STRONG&gt; directory.&lt;BR /&gt;- threatlist.log also shows a successful download&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don't see anything specific in the logs showing an issue processing the download files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In Security Intelligence --&amp;gt; Threat Intelligence --&amp;gt; Threat Artifacts we see where earlier files.&lt;/P&gt;&lt;P&gt;Any other suggestions for where to look to diagnose/resolve this issue.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Aug 2021 05:04:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/TAXII-files-being-downloaded-but-not-processed-by-Enterprise/m-p/564465#M196635</guid>
      <dc:creator>torowa</dc:creator>
      <dc:date>2021-08-24T05:04:22Z</dc:date>
    </item>
  </channel>
</rss>

