Hi Kchamplin,
thanks for your fast response, in the threat artifact list the count is 0 for the stanza that I added together with the status="no_checkpoint_data" therefore I derived that the csv is not read (correctly). Below the stanza from the inputs.conf:
[threatlist://mythreatlistname]
delim_regex = ,
description = mythreatlistname
disabled = 0
fields = discription:$7,ip:$24
ignore_regex = (^#|^\s*$)
interval = 300
retries = 3
retry_interval = 60
skip_header_lines = 0
timeout = 30
type = threatlist
url = lookup://ts_lookup_mythreatlistname
weight = 1
... View more