# Graylog Threat Intel Plugin Results - Stuck in Tail cave

**URL:** <https://community.graylog.org/t/graylog-threat-intel-plugin-results-stuck-in-tail-cave/15764>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [June 3, 2020, 10:11am UTC](https://community.graylog.org/t/graylog-threat-intel-plugin-results-stuck-in-tail-cave/15764 "2020-06-03T10:11:32Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Hari](https://avatars.discourse-cdn.com/v4/letter/h/cdc98d/32.png) [@Hari](https://community.graylog.org/u/Hari)\
**Post date:** [June 15, 2020, 7:38am UTC](https://community.graylog.org/t/graylog-threat-intel-plugin-results-stuck-in-tail-cave/15764/6 "2020-06-15T07:38:07Z")

</div>

2020-06-15 07:09:06,813 WARN [**OTXDataAdapter**] - OTX IPv4 request for key \<169.254.25.10\> failed: Response{protocol=http/1.1, code=400, message= **Bad Request,**  
url=[https://otx.alienvault.com//api/v1/indicators/IPv4/169.254.25.10/general](https://otx.alienvault.com//api/v1/indicators/IPv4/169.254.25.10/general)} - {}

graylog@graylog-graylog3-1:~$ **java -version**  
openjdk version “1.8.0\_232”  
OpenJDK Runtime Environment (build 1.8.0\_232-b09)  
OpenJDK 64-Bit Server VM (build 25.232-b09, mixed mode)  
graylog@graylog-graylog3-1:~$

**Internet connectivity** : Curl to public URL’s are working

**Configuratoin settings of OTX** : /system/lookuptables/data\_adapter/otx-api-ip/edit . We have generated a API key to see if the error messages gets fixed , but no luck . Even with the default settings we had this data adapter warnings . We have made this change **based on the Jan’s recommendation from the older thread**

> [@OTX domain lookup requested but OTX is not enabled in configuration. Please enable it first](https://community.graylog.org/t/otx-domain-lookup-requested-but-otx-is-not-enabled-in-configuration-please-enable-it-first/1409):
>
> Basically, that’s it. I’m getting this error on graylog’s internal log and have no idea how to solve it - Google gives me the first entry as the ThreatIntel plugin github [https://github.com/graylog-labs/graylog-plugin-threatintel/blob/master/src/main/java/org/graylog/plugins/threatintel/providers/otx/OTXLookupProvider.java](https://github.com/graylog-labs/graylog-plugin-threatintel/blob/master/src/main/java/org/graylog/plugins/threatintel/providers/otx/OTXLookupProvider.java) and the rest are two Cisco results, an OpenDNS, and other unrelated stuff. I remember installing the ThreatIntel plugin, because @ionstorm’s Syslog threat intel pipeline us…

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/8/8a96852c7cc396103d722f1803bfe299c2e7b238.png)

So please help us with the break-fix . We can’t afford these warnings in the production environments

---

_[View the full topic](https://community.graylog.org/t/graylog-threat-intel-plugin-results-stuck-in-tail-cave/15764)._
