# Alienvault OTX Missing - Threat Intel Plugin - Graylog 2.4.4

**URL:** <https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176>\
**Category:** Graylog Central (peer support)\
**Created:** [May 7, 2018, 3:02pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176 "2018-05-07T15:02:14Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Digitalpunk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitalpunk/32/1580_2.png) [@Digitalpunk](https://community.graylog.org/u/Digitalpunk)\
**Post date:** [May 7, 2018, 3:02pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/1 "2018-05-07T15:02:14Z")

</div>

I was working to deploy the Alienvault OTX Threat Intel feed listed here: [https://www.graylog.org/post/integrating-threat-intelligence-with-graylog](https://www.graylog.org/post/integrating-threat-intelligence-with-graylog)  
However In my DEV and Prod 2.4.4 Graylog servers I do not see the AlienVault OTX feeds as available.  
I read that the plugin can be downloaded from Github here: [https://github.com/Graylog2/graylog-plugin-threatintel](https://github.com/Graylog2/graylog-plugin-threatintel), but I’m not seeing pre-built JAR files. Do I need to build the JAR files from scratch or was the OTX removed from the plugin purposefully?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 7, 2018, 3:39pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/2 "2018-05-07T15:39:29Z")

</div>

How exactly have you installed Graylog 2.4.4 and where did you look for the AlienVault OTX feed?

> [@Digitalpunk](#):
>
> I read that the plugin can be downloaded from Github here: [GitHub - Graylog2/graylog-plugin-threatintel: Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases](https://github.com/Graylog2/graylog-plugin-threatintel), but I’m not seeing pre-built JAR files.

The Threat Intel plugin has been included as a default plugin since Graylog 2.4.0.

---

<div class="post-metadata">

**Author:** ![Digitalpunk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitalpunk/32/1580_2.png) [@Digitalpunk](https://community.graylog.org/u/Digitalpunk)\
**Post date:** [May 7, 2018, 4:33pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/3 "2018-05-07T16:33:39Z")

</div>

I followed the setup procedures in the manual here: [http://docs.graylog.org/en/latest/pages/installation/os/ubuntu.html](http://docs.graylog.org/en/latest/pages/installation/os/ubuntu.html)

Both are a clustered setup with separate Elasticsearch cluster and MongoDB cluster off-box.  
My primary confusion is that when I configure the Threat Intelligence plugin I do not see the AlienVault OTX as an option to configure like the blog post. All I see is the Tor exit nodes, spamhaus and abuse.ch options.

![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/7/793bda20bc4f2da253b9cbc7a6b0371cd5845d13.png)

Not sure if I’m missing something or if it’s something I haven’t enabled in the config.

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 8, 2018, 7:13am UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/4 "2018-05-08T07:13:51Z")

</div>

There is no configuration setting for AlienVault OTX in the Threat Intelligence plugin configuration (at System / Configurations).

There should be, however, two lookup tables named “Open Thread Exchange (OTX) - IP” and “Open Thread Exchange (OTX) - Domain” on the System / Lookup Tables page.

---

<div class="post-metadata">

**Author:** ![Digitalpunk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitalpunk/32/1580_2.png) [@Digitalpunk](https://community.graylog.org/u/Digitalpunk)\
**Post date:** [May 8, 2018, 3:12pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/5 "2018-05-08T15:12:12Z")

</div>

Ok, I see those. Thanks very much for pointing them out.  
Looking around at those settings I don’t see an option to enter an AlienVault OTX API key. Does Graylog come with its own API keys built-in?

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [May 8, 2018, 3:17pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/6 "2018-05-08T15:17:10Z")

</div>

> [@Digitalpunk](#):
>
> Looking around at those settings I don’t see an option to enter an AlienVault OTX API key.

You can configure your OTX API key in the configuration of the data adapters of the AlienVault OTX lookup tables (see System/Lookup Tables/Data Adapters).

 ![18](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/85d3296e32d7dc6d6058938470716b847ab5f233.png)

---

<div class="post-metadata">

**Author:** ![Digitalpunk](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/digitalpunk/32/1580_2.png) [@Digitalpunk](https://community.graylog.org/u/Digitalpunk)\
**Post date:** [May 8, 2018, 7:16pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/7 "2018-05-08T19:16:16Z")

</div>

Well thanks very much for this. I guess that should have been obvious but I missed it a solid six or so times.  
Much appreciated!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 22, 2018, 7:16pm UTC](https://community.graylog.org/t/alienvault-otx-missing-threat-intel-plugin-graylog-2-4-4/5176/8 "2018-05-22T19:16:19Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
