Knowledge Management

Splunk Enterprise security Custom Threat intel feed

umesh
Path Finder

Hi,

 

We have Configured custom threat intel feeds with splunk. The connection is succesful the status of the file shows "file downloaded". 

I have checked the threat intel audit logs and found some thing here | status="No observables or indicators found in file" stanza="custom feeds"

It is a CSV file and we have checked the ouput by giving the curl command and we got the response as IOC listed in the excel.

but we  found this issue  | status="No observables or indicators found in file" stanza="custom feeds"

Can you help me how to fix this issue . 

Labels (3)
Tags (2)
0 Karma

umesh
Path Finder

The custom threat intel integration is with IOC/stix/STIX2 and we are using Splunk Cloud.

0 Karma

mbozbura
Engager

I have the same issue i have a valid stix2, did you find a solution for this?

0 Karma

DanielPi
Moderator
Moderator

Hi @mbozbura,

I’m a Community Moderator in the Splunk Community.

This question was posted 1 year ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the  visibility it deserves. To increase your chances of getting help from the community, follow these guidelines in the Splunk Answers User Manual when creating your post.

Thank you! 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...