Splunk Enterprise Security

Splunk App for Enterprise Security: Threat lists are downloading, but why are the dashboard and lookups empty?

masplunk
Explorer

New splunk user here and i am hoping someone can help with ES / threatlist problem.

After installing ES and setting up threatlists they appeared to be working correctly, but only a few show up in the dashboard (threatlist activity).

I found threatlists in /opt/splunk/etc/apps/SA-Threatintelligence/lookups, but they are all empty and say "intentionally left empty" and when we do |inputlookup threatlistxxx.csv it gives no results.

I can see from some searches that they ARE downloading and the sizes but I am trying to find out where they are downloaded to? So i am having trouble figuring out why they are not showing up in the dashboards?
Any help would be greatly appreciated !

1 Solution

masplunk
Explorer

Splunk support answered my questions nicely.
Threatlists are downloaded to: /opt/splunk/var/lib/splunk/modinputs/threatlists

To check download date / size, do a ls -lthr. If the dates are current, sizes normal then all is functioning as it should.

The reason we may not be seeing data in our dashboards, is there may be no data in our system that matches the threatlists. To test this I plan on creating a custom threat list with an IP i know we see activity on and hope to see it.

View solution in original post

masplunk
Explorer

Splunk support answered my questions nicely.
Threatlists are downloaded to: /opt/splunk/var/lib/splunk/modinputs/threatlists

To check download date / size, do a ls -lthr. If the dates are current, sizes normal then all is functioning as it should.

The reason we may not be seeing data in our dashboards, is there may be no data in our system that matches the threatlists. To test this I plan on creating a custom threat list with an IP i know we see activity on and hope to see it.

First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...