Getting Data In

Any file size limit of threat intelligence list?

wellchai0914
New Member

Arrcoding to your guide "http://docs.splunk.com/Documentation/ES/4.7.2/Admin/Addthreatintelcustomlookup", I can upload my TI csv into the Splunk host and let the ES to lookup it.
May I know if there is a file size limit (50Mb) of this csv? Is it possible to modify the configuration to increase the file size limit. say 100Mb, and if yes, how to do that. Thanks.

Tags (5)
0 Karma

michael_kushma
Path Finder

The area to change the max file size upload is located below:

https://:/en-US/manager/SplunkEnterpriseSecuritySuite/data/inputs/threat_intelligence_manager

0 Karma
Get Updates on the Splunk Community!

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...