I’m running Graylog 2.40 (which should come with the threat intel plugin) and I have confirmed that the graylog-plugin-threatintel-2.4.3.jar exists in my plugins folder.
I tried testing it by going to a known malware URL (from https://ransomwaretracker.abuse.ch/downloads/TC_C2_DOMBL.txt), which is www.maniffatoretraiteur.com, but in the logs I get:
DestinationHostname_threat_indicated
false
DestinationIp
212.129.14.111
What am I doing wrong?