Hi @Rakzskull,
I’m a Community Moderator in the Splunk Community.
This question was posted 6 years ago, so it might not get the attention you need for your question to be answered. We recommend that you post a new question so that your issue can get the visibility it deserves. To increase your chances of getting help from the community, follow these guidelines in the Splunk Answers User Manual when creating your post.
Thank you!
... View more
Hello @niketn and good day. I just noticed in this answer (super good btw) that you're using a line chart within what it seems to be a statistical table, I've been traying to replicate that same thing, would you be so kind to share the way you accomplish this? I'm using enterprise 9.1.2 on a single node Thanks in advance and best regards.
... View more
@dpreston31 wrote: Did some research and found out that automating VirusTotal lookups is restricted to 4 lookups per minute. Both via VirusTotal Checker's method of appending hashes o a virustotal.com search URL, and via the VT Public API 2.0 access. https://www.virustotal.com/en/documentation/public-api/#getting-ip-reports Explains why in the screenshots he limited the search to 10 events "head 10". Which by the way, successfully works and retrieves VT results only after I go to VirusTotal.com and do the CAPTCHA. i also wanna know why in the screenshots he limited the search to 10 events "head 10"
... View more
Check if you have required app installed on Splunk Cloud search-head, looks you are referring to
VirusTotal Malware Lookup for Splunk: https://splunkbase.splunk.com/app/4283
If not, raise a request for Splunk support for app installation.
... View more
I had our O365 admin use his Admin acct to auth in an incognito window after hitting add. It then has the admin prompt for the access the API/app needs, hit ok... splunk app then adds fine.
... View more