# Graylog OTX every domain is a threat

**URL:** <https://community.graylog.org/t/graylog-otx-every-domain-is-a-threat/12391>\
**Category:** Graylog Add-ons\
**Created:** [October 16, 2019, 6:51am UTC](https://community.graylog.org/t/graylog-otx-every-domain-is-a-threat/12391 "2019-10-16T06:51:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![MartinCo](https://avatars.discourse-cdn.com/v4/letter/m/eada6e/32.png) [@MartinCo](https://community.graylog.org/u/MartinCo)\
**Post date:** [October 16, 2019, 6:51am UTC](https://community.graylog.org/t/graylog-otx-every-domain-is-a-threat/12391/1 "2019-10-16T06:51:12Z")

</div>

Hi, i have installed a plugin for graylog otx threat Intel and made an OTX domain threat indicator. Every time there is a field that has a domain name it will check the domain if its a threat. But for some reason every domain…EVEN [google.com](http://google.com) is a threat. I got the code from the graylog site Integrating Threat Intelligence into Graylog 3+, all i did was change it from src to domain.

So the threat intelligence shows no threat on domain [google.com](http://google.com) but OTX threat intelligence shows a threat.  
So True and False.  
Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 30, 2019, 6:51am UTC](https://community.graylog.org/t/graylog-otx-every-domain-is-a-threat/12391/2 "2019-10-30T06:51:13Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
