Splunk Enterprise Security

Losing data from URL-based Threat Intelligence Feed

aingragunathan
Engager

Hi All,

Looking for some help troubleshooting some odd behaviour around storing IOCs from a custom URL-based Threat Intelligence feed.
We have successfully set it up to a point where we can receive the IOCs (in 2hr intervals), store them and search with them.

But the IOCs seem to randomly disappear. One moment we may have 5000+ IOCs, the next we may have 0 or 2000 or 4000.
Our Threat Intelligence Management page states that the max size DA-ESS-ThreatIntelligence is 100MB and I haven't seen the threat_intel files pass 40MB

Any help troubleshooting this issue is appreciated!

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...