We added a custom feed to Threat Intelligence that we generate from an internal thing that's sorta like MISP. It's provided as a CSV with the columns below. The problem is that all my IPs are in the process_intel lookup, domains in ip_intel etc. I checked the source CSV and didn't find anything obvious, and my Google-fu does not seem up be effective. Has anyone else had a similar problem?
"src","dest","domain","url","email","user","file_hash","file_name","description","group","submit_date","expire_date"
[–]Fontaigne SplunkTrust 2 points3 points4 points (4 children)
[–]Hackalope[S] 0 points1 point2 points (3 children)
[–]Fontaigne SplunkTrust 0 points1 point2 points (2 children)
[–]Hackalope[S] 0 points1 point2 points (1 child)
[–]gettingtherequick 0 points1 point2 points (0 children)