[malware-filter Update botnet_ip.csv] cron_schedule = */15 * * * * description = Update lookup every 15 minutes from 00:00 # https://docs.splunk.com/Documentation/Splunk/latest/SearchReference/Collect#Events_without_timestamps dispatch.earliest_time = 0 enableSched = 0 schedule_window = 5 search = | getbotnetip\ | outputlookup override_if_empty=false botnet_ip.csv [malware-filter Update botnet-filter-splunk.csv] cron_schedule = 0 */12 * * * description = Update lookup every 12 hours from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 60 search = | getbotnetfilter\ | outputlookup override_if_empty=false botnet-filter-splunk.csv [malware-filter Update opendbl_ip.csv] cron_schedule = */15 * * * * description = Update lookup every 15 minutes from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 5 search = | getopendbl\ | outputlookup override_if_empty=false opendbl_ip.csv [malware-filter Update phishing-filter-splunk.csv] cron_schedule = 0 */12 * * * description = Update lookup every 12 hours from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 60 search = | getphishingfilter\ | outputlookup override_if_empty=false phishing-filter-splunk.csv [malware-filter Update pup-filter-splunk.csv] cron_schedule = 0 */12 * * * description = Update lookup every 12 hours from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 60 search = | getpupfilter\ | outputlookup override_if_empty=false pup-filter-splunk.csv [malware-filter Update urlhaus-filter-splunk-online.csv] cron_schedule = 0 */12 * * * description = Update lookup every 12 hours from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 60 search = | geturlhausfilter\ | outputlookup override_if_empty=false urlhaus-filter-splunk-online.csv [malware-filter Update vn-badsite-filter-splunk.csv] cron_schedule = 0 */12 * * * description = Update lookup every 12 hours from 00:00 dispatch.earliest_time = 0 enableSched = 0 schedule_window = 60 search = | getvnbadsitefilter\ | outputlookup override_if_empty=false vn-badsite-filter-splunk.csv