First I'm going to explain the use case I'm working on.
I have the MISP integration working properly. Every day I download the new attributes and publish them in a list to be consumed later by different sources.
This is our configuration:
Now what I want to do is create another miner that feeds from the MISP but downloads only the attributes from a specific Creator org. I want to treat these events differently from others.
According to the documentation (https://github.com/PaloAltoNetworks/minemeld-misp) it seems that it can be done by adding the filter to the node:
I have tried the following configuration, but can't get it to work. When activated Minemeld remains in a corrupt state and is always in starting state. The configuration I have tried is:
Does anyone know if it is possible to filter the events based on the Creator Org?
Thank you in advance,
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!