Splunk Enterprise Security

Splunk ES threat feeds empty

splunkreal
Motivator

Hello guys, since 08/20/2025 we have issues in ES downloading these feeds from Splunk servers. When we try with curl then it doesn't return any data. No error. We use proxy.

Thanks for your help!

 

* If this helps, please upvote or accept solution if it solved *
0 Karma

KeeganP
Engager

Did you ever get a resolution to this? I see nobody has responded, I am in the same boat over here. We recently built up our ES enviro and the threat intel isn't populating for me either. 

0 Karma

splunkreal
Motivator

Hello, we disabled sources which were not available anymore and it's ok now. Support told us provider subscriptions are now required.

* If this helps, please upvote or accept solution if it solved *
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...