I have installed application correctly. but i still don't get the threatscore displayed. I have added the key to file scorelookup.py at /ipreputation/bin/scorelookup.py and restarted splunk. still not working.
sample query tried: index="test" dest_port=80 | stats count by src_ip dst_ip | lookup threatscore clientip AS dst_ip | sort -threatscore
i have even tried with the sample IPs given in scorelookup.py (126.96.36.199) for which i should be getting a score of 35. but its displayed as 0. Pls advice
Thank you of the link,since the post was from 4 years ago,i believe the app works different now. It works on tag=network. i use it only on data that is required, i get the threatscore field, but the scores are displayed as zero. i know atleast some ip should have a score > 0. because i checked the same directly on the website which had given me a score more than 0.
The reason i tried to manually search is because i dint get any results in application dashboard, even after applying filters. its basically a manual search that's running behind the visualisation,so it should have worked in manual search as well. the search query in the question was indeed taken from the application's dashboard.Thanks though. but it dint answer my question.