All Apps and Add-ons

Obelisk Threat Intel: Feed no data

hok2010
New Member

Hello Guys,

I'm stuck with integrating Obelisk threat feed to my test environment.

installed TA add on indexer
installed obelisk threat feed on search head

Always I get a message in index=obelisk

[*] Starting python threat list script. 
[*] Looking for old log files to clear.

I checked whether input files are updated
\obelisk-threat-intel\lookups
but no luck its 0 kb

No files in log folder also [\TA_obelisk-threat\logs].

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...