Getting Data In

remove custom csv file of threat intellignance

riqbal47010
Path Finder

hi

I uploaded custom csv file containing IP addresses.
Referring link "https://docs.splunk.com/Documentation/ES/latest/API/ThreatIntelligenceAPIreference". I have to remove data rows one by one.
there are 400 Ip's against that IP.

So I have to execute this command 400 times ?
PR there is some other way to remove these feeds from threat intelligance KV store.

0 Karma

harsmarvania57
Ultra Champion
0 Karma

riqbal47010
Path Finder

sorry still my problem not solved.

Still the "threat activity detected" is triggering against custom uploaded csv file.

However when I give below command
| inputlookup ip_intel | search threat_key="abc"

I am not seeing any feed datas when I do

and under threat activity dashboard I can see that the custom csv upload threat feed is still ative against
most active threat sources

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...