Splunk Enterprise Security

ES Threat Intel unable to capture hash values from csv upload

att35
Builder

Hi,

I am trying to upload a custom CSV for Threat Intel within ES. It's a collection of multiples types of IOC's, (domain, url, hash etc) and is in the following column format.

CSV_Headers.png

There are 343 Hash values, 20 domains and 8 URL's. Upload goes without any issues and ES collects domains and URL's right away. But Hash values seem to be ignored. Here are the file details under Threat Artifacts.

csv_artifact.png

When I check Threat Intel Audit, it seems to be writing to File Intel as well but hash count never gets populated in ES.

csv_audit.png

What could be going wrong here?

Splunk version: 8.1.1

ES Version: 6.4.0

Thanks,

~ Abhi

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...