Getting Data In

Adding new threat list feed into splunk

astatrial
Contributor

Hello all,
I am having issues with adding AlienVault OTX as a intelligence feed into splunk.
At first, when i didn't configured the threat list as a taxii, it managed to download the threat list as a csv file.
But now, i need to configure it as a taxii for parsing matters and it just stuck on that unhelpful message "TAXII feed polling starting".

My feed configurations are :

Type *
taxii

Description *
Alien Vault OTX feed

URL *
https://otx.alienvault.com/taxii/discovery

Weight *
1

Interval
43200

POST arguments
taxii_username="" taxii_password="poo"

Maximum age
-30d

I am really frustrated and would really appreciate anyone's help.

Thanks

1 Solution

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

View solution in original post

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

alexeyglukhov
Path Finder

could you elaborate a bit please

0 Karma

alexeyglukhov
Path Finder

I assume that was about this python library update

https://github.com/TAXIIProject/libtaxii 

HowardGrace
Engager

Thx for posting!!

0 Karma

infosec2012074
Explorer

Could you please give little bit more detail. 

 

Under contrib directory I see many directories. One of these directories is Directory libtaxii. Do you  mean to change this directory completely ? Is there any trusted source to get the   libtaxii 1.1.114  ?

Get Updates on the Splunk Community!

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

Register Join this Tech Talk to learn how unique features like Service Centric Views, Tag Spotlight, and ...