- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Virustotal Splunk Cloud error

sumanssah
Communicator
06-06-2017
06:40 AM
Getting error while performing below mentioned search
_ index=symantec sourcetype=sep12:risk NOT actual_action= "Details pending" dest_nt_host=* | table dest hash_value | vt field="hash_value"_
Search Factory: Unknown search command 'vt'.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

sumanssah
Communicator
02-29-2020
08:42 PM
Check if you have required app installed on Splunk Cloud search-head, looks you are referring to
VirusTotal Malware Lookup for Splunk: https://splunkbase.splunk.com/app/4283
If not, raise a request for Splunk support for app installation.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Bloodnite
Path Finder
08-31-2017
02:17 PM
you likely need to set the commands.conf value to point to the app's python file, or you're not searching within the app
