How splunk kv store "Ip_intel" or "http_intel" got updated. Is there any saved search behind that.
Where do I see the update interval.
As I can see all my data downloaded from the feed is dumped in SA App threat_intel (Drop Box)
But Iam not sure how it get update to the KV store (http_intel or ip_intel)
Can some one shed a light on this
I believe there is back end search that does that. I am also wondering the same thing.