Determine type of data

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Determine type of data

L3 Networker

Minemeld seems very nice, I'm trying it out in a vm.

 

One thing I'm having a problem with is determining if the information retrieved is going to be an IP list or domain list. Does the processor care if it gets multiple kinds of data?

 

Any other tidbits of information would be beneficial. Thanks! 

1 accepted solution

Accepted Solutions

L7 Applicator

@chirss Don't worry about sending the wrong type of indicators to processors. Processors are configured to ignore type of indicators they cannot process. You can check the infilter section of their prototypes to see the applied filters. 

 

One easy way to check which kind of data is generated by a Miner is checking the LOGS, just click on LOGS at the top right corner of miner and you will see all the indicators generated by that Miner.

 

We are planning to add the type of generated indicators inside the description of each Miner, but that is still in roadmap.

View solution in original post

3 REPLIES 3

L7 Applicator

@chirss Don't worry about sending the wrong type of indicators to processors. Processors are configured to ignore type of indicators they cannot process. You can check the infilter section of their prototypes to see the applied filters. 

 

One easy way to check which kind of data is generated by a Miner is checking the LOGS, just click on LOGS at the top right corner of miner and you will see all the indicators generated by that Miner.

 

We are planning to add the type of generated indicators inside the description of each Miner, but that is still in roadmap.

Cool. I've run into issues adding some inputs which were outputs and then the commit not loving it, then trying to find which feed name to actually remove. Outside of that this seems cool once you get into it. It's kind of what I wish taxii/stix could have been.

We are working to improve usability in the CONFIG section, you should some improvements in the next release or the one after.

 

  • 1 accepted solution
  • 2947 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!