Hi everyone, Am having issues with the configuration of the AlienVault OTX feed in Splunk ES and would appreciate any help. Have got my AlienVault OTX key ready but need help with the Threat Intel taxii feed settings in the web gui. Data inputs » Intelligence Downloads » Type: taxii URL: https://otx.alienvault.com/taxii/discovery POST Arguments: <this is where my key should be placed but how is this formatted??> -> have tried taxii_username="my_key" in the post arguments to no avail. Just keep seeing the "TAXII feed polling starting" message on the "Threat Intelligence Audit" page. Any help is greatly appreciated. Cheers
... View more