Splunk Enterprise Security
Highlighted

Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Communicator

Hello,

I installed the Splunk App for Enterprise Security (simple deployment). I get many error messages :

msg="A threat intelligence download has failed" stanza="alexa_top_one_million_sites" status="threat list could not be written to disk"

msg="A threat intelligence download has failed" stanza="mozilla_public_suffix_list" status="threat list could not be written to disk"

Could someone help me please ?

Regards

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

SplunkTrust
SplunkTrust

I believe this is a known bug.

All you should have to do is find this script - confcheck_failed_threat_download.py and change this line:
job = splunk.search.dispatch(srch, sessionKey=session_key,
earliest=earliest)

to this line:
job = splunk.search.dispatch(srch, sessionKey=session_key,
earliestTime=earliest)

@bosburn_splunk, correct me if I'm wrong.

Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Contributor

That fix was for a different error:
"A threat intelligence download has failed" stanza=“stanza_name" status="threat list download failed after multiple retries"

This one sounds like a permissions issue. Are you running Windows? Have you checked the permissions on the destination file that it's trying to overwrite?

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Communicator

Yes i'M running splunk on Windows.

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Communicator

How could find the destination file ? there was no information about it !

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Explorer

Afef,

If you're running 6.2.3, here is the location of the threatlists. I just found mine and the folder was indeed read only.

C:\Program Files\Splunk\etc\apps\SA-ThreatIntelligence\local\data\threat_intel
0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Contributor

Is it:
earliest_time=earliest
OR
earliestTime=earliest
For this fix? There is a different post with that variation.
Thanks

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Communicator

Hi our ES is 4.5.1. So I checked the confcheckfailedthreatdownload.py. Looks like the line been updated already. Possible the bug been fixed? However, I still getting some error. Most of the stanza been downloaded successfully. Only emergingthreatsipblocklist AND iblocklist_tor download failed.

0 Karma
Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Contributor

Hi, does the host has internet access ? Through a proxy ?
Does the download script runs manualy ?

Highlighted

Re: Splunk App for Enterprise Security: Why am I getting error messages "msg="A threat intelligence download has failed"...status="threat list could not be written to disk""?

Communicator

Hi, no the host didn't have internet access.
Which script ?

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.