We have noticed a message saying that the Splunk threat intelligence download has failed. Got the below error. Can someone advise on this?
A threat intelligence download has failed. stanza="maxmin_geoip_asn_ipv4" host="xxxx" status="threat list download failed after multiple retries"
The base URL for "maxmind_geoip_asn_ipv4" threat list is https://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum2.zip
However, this now throws a 404 error when accessed. It looks like MaxMind \ GeoLite has changed their download URL.
From here: https://download.maxmind.com/download/geoip/database/asnum/
To: https://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip
Note that that new *.zip contains both: GeoLite2-ASN-Blocks-IPv4.csv and GeoLite2-ASN-Blocks-IPv6.csv.
This has been notified to Splunk engineering team via SOLNESS-17731. Currently, this framework does not support the ES and an ER was requested but closed as won’t fix. If you would like to use other subscription-based services you are welcome to do so.
In general, the third-party Intelligence Downloads are out of our control, which is why I guess the troubleshooting guide is so trite or to the point:
The base URL for "maxmind_geoip_asn_ipv4" threat list is https://download.maxmind.com/download/geoip/database/asnum/GeoIPASNum2.zip
However, this now throws a 404 error when accessed. It looks like MaxMind \ GeoLite has changed their download URL.
From here: https://download.maxmind.com/download/geoip/database/asnum/
To: https://geolite.maxmind.com/download/geoip/database/GeoLite2-ASN-CSV.zip
Note that that new *.zip contains both: GeoLite2-ASN-Blocks-IPv4.csv and GeoLite2-ASN-Blocks-IPv6.csv.
This has been notified to Splunk engineering team via SOLNESS-17731. Currently, this framework does not support the ES and an ER was requested but closed as won’t fix. If you would like to use other subscription-based services you are welcome to do so.
In general, the third-party Intelligence Downloads are out of our control, which is why I guess the troubleshooting guide is so trite or to the point: