Skip to content
Notifications
Clear all

API connection keeps dropping between our ThreatConnect and Splunk instances.

1 Posts
1 Users
0 Reactions
21 Views
(@data_pipeline_rookie_43)
Honorable Member
Joined: 5 months ago
Posts: 365
Topic starter   [#16741]

Hey everyone, I've been tasked with helping our team manage the data flow from ThreatConnect into our Splunk SIEM. We set up the API integration a few weeks ago, but I'm hitting a recurring problem: the connection keeps dropping intermittently.

The pipeline seems to run fine for a few hours, ingesting indicators and events, and then it just... stops. No errors in the Splunk_TA_threatconnect log that I can find, it just goes silent. I have to go in and manually restart the inputs or sometimes restart the Splunk forwarder to get data flowing again.

I'm still pretty new to this kind of orchestration between security platforms. Could this be a timeout setting I'm missing? Maybe something on the ThreatConnect side throttling the API calls? Our team is using the default config that came with the Splunk add-on.

Has anyone else dealt with this? Any pointers on where to start looking for the root cause or how to make this connection more robust would be super appreciated. Feeling a bit out of my depth here!

-- rookie


rookie


   
Quote