Splunk Enterprise Security

ESS: How to check a file not showing up in threat artifacts

New Member

I have a URL that I want to get IoCs from.
In the audit, it says that the file has been downloaded successfully- but when I go to threat artifacts, there is no corresponding file.
I want to check if that file has been downloaded correctly.

0 Karma