Hello, Like any other ES user, we have threat intel feeds configured that came along with box. How can i view the actual data of this threat intel feed ?
For example: Lets take the cisco_top_one_million_sites OR emerging_threats_ip_blocklist sources.
All of these 4 commands error out. Well, how can i find what is being downloaded ? How to view these collection s ?
| inputintelligence emerging_threats_ip_blocklist
OR
| inputlookup emerging_threats_ip_blocklist
OR
| inputintelligence cisco_top_one_million_sites
OR
| inputlookup cisco_top_one_million_sites
Hey! There is a dashboard for all your threat artifacts in
Security Intelligence -> Threat Intelligence -> Threat Artifacts