Splunk Enterprise Security

Maxmind Threat Intelligence Database is not downloading

josephliion
Explorer

Hi there, I noticed that the URL path for the MaxMind ASN Database has changed on, to another path, and the siem can research for the file.

alt text
alt text

When I tried to put the new path, I realize that the zip file has a folder with two files and it is unreadable for the Splunk

¿Anyone has the same problem? ¿Is there another way to update the threat intelligence with IP Geolocation?

Best Regards,
Jose León

tommoore
Path Finder

Anyone know if this has been fixed yet?

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee

Hi,

There are several Splunkbase Apps around this, with one of the latest being the : ASN Lookup Generator

https://splunkbase.splunk.com/app/3531

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Where are you using the ASN file? Splunk ships with GeoLite2-City.mmdb, which is all that you should need to update.

---
If this reply helps you, Karma would be appreciated.
0 Karma

kaw243
Explorer

The ASN file is used in ES in the below lookup Gens

Threat - ASN CIDR Matches - Lookup Gen
Threat - ASN IPv6 CIDR Matches - Lookup Gen
Threat - ASN String Matches - Lookup Gen

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee

Hi Jose,

This has been identified as an issue to be addressed under SOLNESS-17731
- " Name and location of the MaxMind GeoIP database has changed "

At present others are using the workaround of extracting the downloaded zip folder to a hosted web server or e.g. github repository.

Hope it helps,
Cheers,
Matt - Splunk.

0 Karma

rragazan
Loves-to-Learn Lots

Hi @mdillon_splunk

There is now a requirement that we and other users first obtain a free license key from MaxMind (https://blog.maxmind.com/2019/12/18/significant-changes-to-accessing-and-using-geolite2-databases/) and update the link to take this into account such that the URL becomes "https://download.maxmind.com/app/geoip_download?edition_id=GeoLite2-ASN-CSV&license_key=INSERT_LICEN...".

The reason I'm raising this after quite some time since the last post on this thread is that I'm wondering whether "SOLNESS-17731" is also planning to take into account that the backend Python code that Splunk uses for this functionality (called "threatlist.py" & "protocols.py") seems to currently be unable to process archives which have multiple files within, as the screenshot below from my experimentation shows:

MultiFileArchiveProblem.png

 

The problem here is that MaxMind currently doesn't provide these files except as part of a ZIP or TAR.GZ archive with the following multi-file structure:

Folder: GeoLite2-ASN-CSV_20200728

File underneath: GeoLite2-ASN-Blocks-IPv4.csv

File underneath: COPYRIGHT.txt

File underneath: GeoLite2-ASN-Blocks-IPv6.csv

File underneath: LICENSE.txt

 

Thus, it would be ideal if we could somehow specify a configuration parameter when setting up the input like "File location: GeoLite2-ASN-CSV_YYYYmmdd/GeoLite2-ASN-Blocks-IPv4.csv" so that we can select which file Splunk will parse out of the archive.

We have a use case which relies on these CIDR IP <> ASN mappings so it would be great to get an update on whether something like the above has been considered as part of "SOLNESS-17731"; also could you please let me know if this should rather be raised as a Splunk Idea instead.

 

Many thanks !

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee

Hi @rragazan 

The issue should now be addressed with Enterprise Security 6.2.0

https://docs.splunk.com/Documentation/ES/6.2.0/RN/FixedIssues

SOLNESS-22110   - Threat Intelligence: Maxmind ASN database can no longer be consumed

0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...