Splunk Enterprise Security

Force Threat Intelligence download

matthewhintz
New Member

Greetings,

For ES, is there a way to force the threat intelligence feeds to download? I think they default run on a 12 hour schedule but would like to be able to force a download if necessary.

0 Karma
1 Solution

Azeemering
Builder

You can set the interval per Intelligence Download under Configure->Data Enrichment->Intelligence Downloads.
Here you can specify the interval per feed.
Default for most is 86400 seconds

View solution in original post

0 Karma

matthewhintz
New Member

I would prefer to be able to simply force it but it is as I suspected. I must change the update interval to something like 60 seconds and then change it back to what I want to run normally.

0 Karma

Azeemering
Builder

You can set the interval per Intelligence Download under Configure->Data Enrichment->Intelligence Downloads.
Here you can specify the interval per feed.
Default for most is 86400 seconds

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...