Splunk Enterprise Security

Enterprise Security - SA-ThreatIntelligence - Checkpoint file error

fabiob
Explorer

Hello,

I'm troubleshooting an error I get with SA-ThreatIntelligence in ES: in Data inputs » Threat Lists, I have several data inputs, i.e. URLs from which txt files are downloaded and then converted in csv files.

While the download is performed without errors, I keep on receiving this error during a following step (/opt/splunk/var/log/splunk/python_modular_input.log):

ERROR pid=16393 tid=MainThread file=lookup_modinput.py:collect_files:145 | status="Checkpoint file error" err="unknown path or update time" name=spyeye_ip_blocklist category=threatlist

I think it occurs when the app tries to take the downloaded txt and to convert it to CSV. If I edit the python file lookup_modinput.py to print other variables, I get:

name=spyeye_ip_blocklist path=None last_updated=None

but I don't know why they're not initialized.

Does anyone have any hint about this?
Thanks!

season88481
Contributor

I got the same error when ES trying to download a lookup called "icann_top_level_domain_list".
Any comment?

0 Karma

sf_user_199
Path Finder

Do any of the downloads & merges function? If so, I would disabled all and turn them back on one by one until you narrow down to the threatlist download that is failing.

Alternatively:

-disable all of the lists
-clone one of the disabled threatlist downloads and enable the clone. If that works then you may need to recreate the threatlist downloads. This fixed some of the custom threatlists that seemed to get stuck for me.

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...