by default, where from threat Intelligence feed downloaded in splunk ?
For ES Threat Intel downloads, go to Configure -> Data Enrichment -> Intelligence Downloads. This screen shows you the feed status(Enabled or not) and also the URL it will reach out to download the Intel.