Splunk Enterprise Security

Losing data from URL-based Threat Intelligence Feed

aingragunathan
Engager

Hi All,

Looking for some help troubleshooting some odd behaviour around storing IOCs from a custom URL-based Threat Intelligence feed.
We have successfully set it up to a point where we can receive the IOCs (in 2hr intervals), store them and search with them.

But the IOCs seem to randomly disappear. One moment we may have 5000+ IOCs, the next we may have 0 or 2000 or 4000.
Our Threat Intelligence Management page states that the max size DA-ESS-ThreatIntelligence is 100MB and I haven't seen the threat_intel files pass 40MB

Any help troubleshooting this issue is appreciated!

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...