- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are attempting to setup local lookup file as a threat intelligence download
data:image/s3,"s3://crabby-images/d3347/d334703afb9bf63c7e394bcc57339c603c832da2" alt="rbal_splunk rbal_splunk"
rbal_splunk
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Splunk Employee
08-06-2019
09:46 AM
( as per https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Addthreatintelcustomlookup) . and are unable to use this intelligence list with the "inputintelligence" command. Also, we see error like "Failed to read threatlist /opt/splunk/var/lib/splunk/modinputs/threatlist/oculus"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/7cc40/7cc40a8e0df68dcec9463e634d708beade29c09a" alt="dzejsonborn dzejsonborn"
dzejsonborn
New Member
08-30-2019
03:23 AM
Can I use "| inputintelligence" in the correlation search ?
| eval TOR="danme_tor_node_list_with_ports"
| lookup "danme_tor_node_list_with_ports" ip as All_Traffic.src_ip OUTPUT ip name
| where isnotnull(ip)
??? still does not work
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
data:image/s3,"s3://crabby-images/d3347/d334703afb9bf63c7e394bcc57339c603c832da2" alt="rbal_splunk rbal_splunk"
rbal_splunk
data:image/s3,"s3://crabby-images/1f594/1f594b1b4c0941863df1722dd52dd06a5b9a2e11" alt="Splunk Employee Splunk Employee"
Splunk Employee
08-06-2019
09:46 AM
you can only use "| inputintelligence" on non-threat intelligence...given it's a local lookup you can just use "| inputlookup" ?
data:image/s3,"s3://crabby-images/5d9f8/5d9f80c54160124d38856b77a799077db7d57026" alt=""