MISP - Filter events/attributes

cancel
Showing results for 
Search instead for 
Did you mean: 

MISP - Filter events/attributes

L0 Member

Hi all, 

 

First I'm going to explain the use case I'm working on.

I have the MISP integration working properly. Every day I download the new attributes and publish them in a list to be consumed later by different sources.

 

This is our configuration:

 

acouceiro_1-1625047104452.png

 

Now what I want to do is create another miner that feeds from the MISP but downloads only the attributes from a specific Creator org. I want to treat these events differently from others.

According to the documentation (https://github.com/PaloAltoNetworks/minemeld-misp) it seems that it can be done by adding the filter to the node:

 

acouceiro_2-1625047377143.png

 

I have tried the following configuration, but can't get it to work. When activated Minemeld remains in a corrupt state and is always in starting state. The configuration I have tried is:

 

acouceiro_3-1625047622945.png

 

Does anyone know if it is possible to filter the events based on the Creator Org?

 

Thank you in advance, 

Best regards.

0 REPLIES 0
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!