Splunk Enterprise Security

Splunk App for Enterprise Security: How to troubleshoot if the Threat Intelligence Source data is actually being downloaded?

trross33
Path Finder

After configuring the proxy settings for downloading the Splunk for Enterprise Security Intelligence Source data, I am still receiving errors indicating the download has failed. I know this is a reported bug, however, I want to be able to confirm this data is actually downloading. Where can I find whether or not the data is really downloading from the Threat Intelligence sources? It seems there use to be a report for this, but I can't seem to find it. Thanks.

0 Karma

greich
Communicator

1- from the UI: Audit / Threat Intelligence Audit
2- from the command line
ls -l $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/data/threat_intel/

Get Updates on the Splunk Community!

Admin Your Splunk Cloud, Your Way

Join us to maximize different techniques to best tune Splunk Cloud. In this Tech Enablement, you will get ...

Cloud Platform | Discontinuing support for TLS version 1.0 and 1.1

Overview Transport Layer Security (TLS) is a security communications protocol that lets two computers, ...

New Customer Testimonials

Enterprises of all sizes and across different industries are accelerating cloud adoption by migrating ...