Hey gents
My customer is asking me to create a new threatintelligencesource in the Enterprise Security app (version 4.5.1.)
He told me that he is going to provide an .ioc file with the f...
As per the URL
http://docs.splunk.com/Documentation/ES/4.2.0/User/Configureblocklists
We are looking for : Add a URL-based threatsource -> ThreatIntelligence Downloads.
After c...
In the documentation at https://docs.splunk.com/Documentation/ES/7.0.2/Admin/Changethreatintel under
Review the logic for retention the document states, "The threat retention input runs e...
I have a problem, I recently started using the Splunk Theat Intelligence Management (TRU STAR) platform, which is our IOC management tools that contain different sources of intelligence.
The tool h...
Hello,
I added a new threatintelligencesource in Splunk Enterprise Security (https://ransomwaretracker.abuse.ch/feeds/csv/ ). The download works fine and the list is stored in /opt/splunk/etc/a...
Hi,
I have a intelligence lookup file in SA-ThreatIntelligence APP.
This lookup schedule content update with open source intelligencesources.
I am using Threatintelligence on Splunk E...
...eported bug, however, I want to be able to confirm this data is actually downloading. Where can I find whether or not the data is really downloading from the ThreatIntelligencesources? It seems t...
We are having an issue where a single threatintelligence download is failing (SANS blocklist) regularly. I can wget the file just fine from the search head where Splunk Enterprise Security is i...
...ositives.
We removed the feeds from Settings > Data Inputs > ThreatIntelligence Downloads, ensured all CSV files were not in any DA-ESS-Threat* subfolder and all SA-Threat* subfolder.
R...