- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Splunk Enterprise Security: How to troubleshoot why a Threat Intelligence download is failing for a single download source?
We are having an issue where a single threat intelligence download is failing (SANS blocklist) regularly. I can wget the file just fine from the search head where Splunk Enterprise Security is installed, so I'm not sure it's a network problem with reaching the site. Is there any place I can get a more specific error message as to why this is failing?
msg="A threat intelligence download has failed" stanza="sans" status="threat list download failed after multiple retries"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/f2c43/f2c43ff9fe30701b4ec7d60d5201063534e5c1eb" alt="SplunkTrust SplunkTrust"
I logged a case on 4.7.0, I believe the issue will get fixed in 4.7.2
As a workaround, you can edit :
/opt/splunk/etc/apps/DA-ESS-ThreatIntelligence/bin/configuration_checks/confcheck_failed_threat_download.py as below
Change:
job = splunk.search.dispatch(search_string, sessionKey=session_key, earliest=earliest)
To:
job = splunk.search.dispatch(search_string, sessionKey=session_key, earliest_time=earliest)
The difference on that last line is the earliest_time= setting....once I did that the warnings went away.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/16020/1602035bcc8d8c0df31a720d0bf5139b2b8acdbd" alt="salbro salbro"
Was there ever a resolution to this? I have this problem after upgrading to ES 4.7.1
data:image/s3,"s3://crabby-images/d7f73/d7f73632dd731f9b3dd280d9d048df61ba67932c" alt=""