Installation

IP Reputation threatscore not working.

prithvi08
Engager

Hi,

I have installed application correctly. but i still don't get the threatscore displayed. I have added the key to file scorelookup.py at /ipreputation/bin/scorelookup.py and restarted splunk. still not working.

sample query tried: index="test" dest_port=80 | stats count by src_ip dst_ip | lookup threatscore clientip AS dst_ip | sort -threatscore

i have even tried with the sample IPs given in scorelookup.py (14.139.155.194) for which i should be getting a score of 35. but its displayed as 0. Pls advice

0 Karma

p_gurav
Champion
0 Karma

prithvi08
Engager

Hi
Thank you of the link,since the post was from 4 years ago,i believe the app works different now. It works on tag=network. i use it only on data that is required, i get the threatscore field, but the scores are displayed as zero. i know atleast some ip should have a score > 0. because i checked the same directly on the website which had given me a score more than 0.

0 Karma

mayurr98
Super Champion
0 Karma

prithvi08
Engager

The reason i tried to manually search is because i dint get any results in application dashboard, even after applying filters. its basically a manual search that's running behind the visualisation,so it should have worked in manual search as well. the search query in the question was indeed taken from the application's dashboard.Thanks though. but it dint answer my question.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...