Getting Data In

Adding new threat list feed into splunk

astatrial
Contributor

Hello all,
I am having issues with adding AlienVault OTX as a intelligence feed into splunk.
At first, when i didn't configured the threat list as a taxii, it managed to download the threat list as a csv file.
But now, i need to configure it as a taxii for parsing matters and it just stuck on that unhelpful message "TAXII feed polling starting".

My feed configurations are :

Type *
taxii

Description *
Alien Vault OTX feed

URL *
https://otx.alienvault.com/taxii/discovery

Weight *
1

Interval
43200

POST arguments
taxii_username="" taxii_password="poo"

Maximum age
-30d

I am really frustrated and would really appreciate anyone's help.

Thanks

1 Solution

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

View solution in original post

astatrial
Contributor

The problem was with libtaxii 1.1.111, which i changed to 1.1.114. in the path :
/etc/apps/SA-ThreatIntelligence/contrib

Problem fixed.

alexeyglukhov
Path Finder

could you elaborate a bit please

0 Karma

alexeyglukhov
Path Finder

I assume that was about this python library update

https://github.com/TAXIIProject/libtaxii 

HowardGrace
Engager

Thx for posting!!

0 Karma

infosec2012074
Explorer

Could you please give little bit more detail. 

 

Under contrib directory I see many directories. One of these directories is Directory libtaxii. Do you  mean to change this directory completely ? Is there any trusted source to get the   libtaxii 1.1.114  ?

Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...