- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk App for Enterprise Security: How to troubleshoot if the Threat Intelligence Source data is actually being downloaded?
trross33
Path Finder
10-16-2015
01:59 PM
After configuring the proxy settings for downloading the Splunk for Enterprise Security Intelligence Source data, I am still receiving errors indicating the download has failed. I know this is a reported bug, however, I want to be able to confirm this data is actually downloading. Where can I find whether or not the data is really downloading from the Threat Intelligence sources? It seems there use to be a report for this, but I can't seem to find it. Thanks.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

greich
Communicator
06-03-2016
07:11 AM
1- from the UI: Audit / Threat Intelligence Audit
2- from the command line
ls -l $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data/threat_intel/
