Hi,
I am trying to upload a custom CSV for Threat Intel within ES. It's a collection of multiples types of IOC's, (domain, url, hash etc) and is in the following column format.
There are 343 Hash values, 20 domains and 8 URL's. Upload goes without any issues and ES collects domains and URL's right away. But Hash values seem to be ignored. Here are the file details under Threat Artifacts.
When I check Threat Intel Audit, it seems to be writing to File Intel as well but hash count never gets populated in ES.
What could be going wrong here?
Splunk version: 8.1.1
ES Version: 6.4.0
Thanks,
~ Abhi