- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
alert triggered but ip not available in csv

srisahitya_v
Communicator
06-21-2018
08:02 AM
Hello Folks,
I have enabled a notable in ES_app, which triggers if it finds any ip available from local_ip_intel.csv.
Now I got a notable for one IP address, which I don't want it present in that list.
when I start searching, that IP is not available in local_ip_intel.csv.
but i can see a foot print in "ES_App"-->"Threat Artifacts"--> "network" dashboard with source path "/opt/splunk/etc/apps/DA-ESS-ThreatIntelligence/lookups/local_ip_intel.csv"
What might be causing, this false alert from ES_app where IP is not available in source csv file.
