Splunk Enterprise Security

threat list download failed after multiple retries

ybahat
New Member

The splunk server is located behind a proxy, and i'm getting a lot of "threat list download failed after multiple retries" error messages.

From my logs I can see that the download is attempted directly, and not through the proxy.
What do I need to configure and where?

0 Karma

shellsam
Explorer

I too have the same issue.but i had configured the proxy

0 Karma

tskinnerivsec
Contributor

I am working on this myself, still getting failures after configuring proxy info. Does proxy server field need to be populated in http:\ format, or does just the ip address of the proxy suffice in that field?

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Just enter the hostname or ip address.
Note also there were a bug in older versions if you were using proxy authentication under certain conditions (I assume it is resolved now). Are you using authentication ?

If it does not work, look for your proxy logs in Splunk 🙂

0 Karma

mdessus_splunk
Splunk Employee
Splunk Employee

Hello, you need to configure first the proxy setting in each threat (Configure / Data Enrichment / Threat list), and if needed authentication in Configure / General / Credential management. And it should work !

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...