Splunk Enterprise Security

Splunk App for Enterprise Security: How to troubleshoot if the Threat Intelligence Source data is actually being downloaded?

trross33
Path Finder

After configuring the proxy settings for downloading the Splunk for Enterprise Security Intelligence Source data, I am still receiving errors indicating the download has failed. I know this is a reported bug, however, I want to be able to confirm this data is actually downloading. Where can I find whether or not the data is really downloading from the Threat Intelligence sources? It seems there use to be a report for this, but I can't seem to find it. Thanks.

0 Karma

greich
Communicator

1- from the UI: Audit / Threat Intelligence Audit
2- from the command line
ls -l $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data/threat_intel/

Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...