All Apps and Add-ons

Virustotal isn't caching

gregzee
New Member

My expectations are that whenever I run

My search:

| fields <>
| lookup virustotal_url_cache vt_urls AS url OUTPUT vt_positives, vt_classification, vt_threat_id
| virustotal url=url rescan=false
| table <>

Whatever isn't cached it will hit the API, if it has been searched, it will return the results, and cache it in the KVStore.

This hasn't been happening. Also, nothing has been cached to begin with. I ran a test on 8.8.8.8 and nothing returns.

I am running Splunk Cloud.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...