All Apps and Add-ons

Obelisk Threat Intel: Feed no data

hok2010
New Member

Hello Guys,

I'm stuck with integrating Obelisk threat feed to my test environment.

installed TA add on indexer
installed obelisk threat feed on search head

Always I get a message in index=obelisk

[*] Starting python threat list script. 
[*] Looking for old log files to clear.

I checked whether input files are updated
\obelisk-threat-intel\lookups
but no luck its 0 kb

No files in log folder also [\TA_obelisk-threat\logs].

0 Karma
Get Updates on the Splunk Community!

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...