Hello Folks,
I have enabled a notable in ES_app, which triggers if it finds any ip available from local_ip_intel.csv.
Now I got a notable for one IP address, which I don't want it present in that list.
when I start searching, that IP is not available in local_ip_intel.csv.
but i can see a foot print in "ES_App"-->"Threat Artifacts"--> "network" dashboard with source path "/opt/splunk/etc/apps/DA-ESS-ThreatIntelligence/lookups/local_ip_intel.csv"
What might be causing, this false alert from ES_app where IP is not available in source csv file.