Hello guys, since 08/20/2025 we have issues in ES downloading these feeds from Splunk servers. When we try with curl then it doesn't return any data. No error. We use proxy.
Thanks for your help!
phishtank | https://data.phishtank.com/data/online-valid.csv.gz |
iblocklist_piratebay | https://list.iblocklist.com/?list=nzldzlpkgrcncdomnttb |
iblocklist_web_attacker | https://list.iblocklist.com/?list=ghlzqtqxnzctvvajwwag |
iblocklist_tor | https://list.iblocklist.com/?list=tor |
iblocklist_logmein | https://list.iblocklist.com/?list=logmein |
iblocklist_proxy | https://list.iblocklist.com/?list=bt_proxy |
iblocklist_rapidshare | https://list.iblocklist.com/?list=zfucwtjkfwkalytktyiw |
mozilla_public_suffix_list | https://publicsuffix.org/list/effective_tld_names.dat |
Did you ever get a resolution to this? I see nobody has responded, I am in the same boat over here. We recently built up our ES enviro and the threat intel isn't populating for me either.
Hello, we disabled sources which were not available anymore and it's ok now. Support told us provider subscriptions are now required.