Installation

IP Reputation threatscore not working.

prithvi08
Engager

Hi,

I have installed application correctly. but i still don't get the threatscore displayed. I have added the key to file scorelookup.py at /ipreputation/bin/scorelookup.py and restarted splunk. still not working.

sample query tried: index="test" dest_port=80 | stats count by src_ip dst_ip | lookup threatscore clientip AS dst_ip | sort -threatscore

i have even tried with the sample IPs given in scorelookup.py (14.139.155.194) for which i should be getting a score of 35. but its displayed as 0. Pls advice

0 Karma

p_gurav
Champion
0 Karma

prithvi08
Engager

Hi
Thank you of the link,since the post was from 4 years ago,i believe the app works different now. It works on tag=network. i use it only on data that is required, i get the threatscore field, but the scores are displayed as zero. i know atleast some ip should have a score > 0. because i checked the same directly on the website which had given me a score more than 0.

0 Karma

mayurr98
Super Champion
0 Karma

prithvi08
Engager

The reason i tried to manually search is because i dint get any results in application dashboard, even after applying filters. its basically a manual search that's running behind the visualisation,so it should have worked in manual search as well. the search query in the question was indeed taken from the application's dashboard.Thanks though. but it dint answer my question.

0 Karma
Get Updates on the Splunk Community!

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...

Getting Started with AIOps: Event Correlation Basics and Alert Storm Detection in ...

Getting Started with AIOps:Event Correlation Basics and Alert Storm Detection in Splunk IT Service ...

Register to Attend BSides SPL 2022 - It's all Happening October 18!

Join like-minded individuals for technical sessions on everything Splunk!  This is a community-led and run ...