Getting Data In

Adding new threat list feed into splunk

astatrial
Contributor

Hello all,
I am having issues with adding AlienVault OTX as a intelligence feed into splunk.
At first, when i didn't configured the threat list as a taxii, it managed to download the threat list as a csv file.
But now, i need to configure it as a taxii for parsing matters and it just stuck on that unhelpful message "TAXII feed polling starting".

My feed configurations are :

Type *
taxii

Description *
Alien Vault OTX feed

URL *
https://otx.alienvault.com/taxii/discovery

Weight *
1

Interval
43200

POST arguments
taxii_username="" taxii_password="poo"

Maximum age
-30d

I am really frustrated and would really appreciate anyone's help.

Thanks

1 Solution

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

View solution in original post

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

alexeyglukhov
Path Finder

could you elaborate a bit please

0 Karma

alexeyglukhov
Path Finder

I assume that was about this python library update

https://github.com/TAXIIProject/libtaxii 

HowardGrace
Engager

Thx for posting!!

0 Karma

infosec2012074
Explorer

Could you please give little bit more detail. 

 

Under contrib directory I see many directories. One of these directories is Directory libtaxii. Do you  mean to change this directory completely ? Is there any trusted source to get the   libtaxii 1.1.114  ?

Get Updates on the Splunk Community!

There's No Place Like Chrome and the Splunk Platform

Watch On DemandMalware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

The Great Resilience Quest: 5th Leaderboard Update

The fifth leaderboard update for The Great Resilience Quest is out >> 🏆 Check out the ...

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...