We are working on getting our Splunk Enterprise Security environment working properly and have it mostly sorted out, but are receiving threat list download errors like this:
msg="A threat intelligence download has failed" stanza="palevo_ip_blocklist" status="threat list download failed after multiple retries"
I should note that I am somewhat of a Splunk newbie, so it is very possible I have missed something.
Hello. Does the search head with ES installed on it have access to the Internet? Are other threat lists downloading?
Yes it does have access to the Internet and the error seems to be happening for multiple threat lists.
Can you run the following search string and send the output so we can see which lists are failing?
index=internal source=*configurationcheck.log task=confcheckfailedthreat_download | stats values(stanza)
Hi I have the same issue. By using this search query: index=internal source=*configurationcheck.log task=confcheckfailedthreat_download | stats values(stanza)
I only got two stanza: emergingthreatsipblocklist AND iblocklisttor. Other stanza seems being downloaded OK.
Also tried the answer from this https://answers.splunk.com/answers/248909/splunk-app-for-enterprise-security-why-am-i-gettin-1.html
No joy either.
This turned out to be an issue of the system being moved and the boot-start enabled so it was trying to download the lists prior to having full Internet access. Sorry for the confusion and thanks for the help!