Installation

IP Reputation threatscore not working.

prithvi08
Engager

Hi,

I have installed application correctly. but i still don't get the threatscore displayed. I have added the key to file scorelookup.py at /ipreputation/bin/scorelookup.py and restarted splunk. still not working.

sample query tried: index="test" dest_port=80 | stats count by src_ip dst_ip | lookup threatscore clientip AS dst_ip | sort -threatscore

i have even tried with the sample IPs given in scorelookup.py (14.139.155.194) for which i should be getting a score of 35. but its displayed as 0. Pls advice

0 Karma

p_gurav
Champion
0 Karma

prithvi08
Engager

Hi
Thank you of the link,since the post was from 4 years ago,i believe the app works different now. It works on tag=network. i use it only on data that is required, i get the threatscore field, but the scores are displayed as zero. i know atleast some ip should have a score > 0. because i checked the same directly on the website which had given me a score more than 0.

0 Karma

mayurr98
Super Champion
0 Karma

prithvi08
Engager

The reason i tried to manually search is because i dint get any results in application dashboard, even after applying filters. its basically a manual search that's running behind the visualisation,so it should have worked in manual search as well. the search query in the question was indeed taken from the application's dashboard.Thanks though. but it dint answer my question.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...