Troubleshoot failed intelligence downloads in Splunk Enterprise Security
If you receive the message that a threat list failed to download, there are several possible root causes.
Possible root cause | Verification | Mitigation |
---|---|---|
The threat or intelligence source is no longer available at the IP address or URL. | Attempt to visit the URL or curl the threat source manually. | Disable the intelligence source if it is no longer available to download. |
Firewall or proxy settings are preventing the intelligence source from being accessed. | Test if you can visit the URL or curl the intelligence source manually on a different machine. | Modify the firewall or proxy settings to allow access to the intelligence source. |
Troubleshoot messages about unnecessary read or write access to investigation KV store collections | Troubleshoot dashboards in Splunk Enterprise Security |
This documentation applies to the following versions of Splunk® Enterprise Security: 7.0.1, 7.0.2, 7.1.0, 7.1.1, 7.1.2, 7.2.0, 7.3.0, 7.3.1, 7.3.2
Feedback submitted, thanks!