Splunk Enterprise Security

Splunk Enterprise Security: Why am I getting threat list "download has failed" errors?

tryan65
Explorer

Hi Folks,

We are working on getting our Splunk Enterprise Security environment working properly and have it mostly sorted out, but are receiving threat list download errors like this:

msg="A threat intelligence download has failed" stanza="palevo_ip_blocklist" status="threat list download failed after multiple retries"

I should note that I am somewhat of a Splunk newbie, so it is very possible I have missed something.

Thanks!

0 Karma
1 Solution

gtriSplunk
Path Finder

Hello. Does the search head with ES installed on it have access to the Internet? Are other threat lists downloading?

View solution in original post

gtriSplunk
Path Finder

Hello. Does the search head with ES installed on it have access to the Internet? Are other threat lists downloading?

tryan65
Explorer

Hello,

This turned out to be an issue of the system being moved and the boot-start enabled so it was trying to download the lists prior to having full Internet access. Sorry for the confusion and thanks for the help!

0 Karma

tryan65
Explorer

Hello,

Yes it does have access to the Internet and the error seems to be happening for multiple threat lists.

0 Karma

gtriSplunk
Path Finder

Can you run the following search string and send the output so we can see which lists are failing?

index=_internal source=*configuration_check.log task=confcheck_failed_threat_download | stats values(stanza)

0 Karma

season88481
Contributor

Hi I have the same issue. By using this search query: index=_internal source=*configuration_check.log task=confcheck_failed_threat_download | stats values(stanza)

I only got two stanza: emerging_threats_ip_blocklist AND iblocklist_tor. Other stanza seems being downloaded OK.

Also tried the answer from this https://answers.splunk.com/answers/248909/splunk-app-for-enterprise-security-why-am-i-gettin-1.html

No joy either.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...