Do you know something sample about integration with MISP (Malware Information share platform)???
So another question is about scripts, can I launch a script into conifg a new prototype? If I've created a new prototype I set a url option...can I set the url option for script option????
Thanks a lot
I succeeded in using MISP extension in order to get data from a misp server...but now I cannot
export data via output node.
No luck so far...on the output node I see non zero statistics for
updated.queue, update.rx, withdraw.processed, withdraw.queued, withdraw.rx
while zero value for
checkpoint.* and removed
If I try to connect to the FEED BASE URL of the output node I get status 200 but a blank page.
I'm probably overlooking some important point...
could you check in the Miner LOGS which type of share level is applied to the indicators ?
Go to the MISP Miner and click on LOGS, there you will see the extracted indicators. If you click on one of them you will see the full list of attributes assigned to the indicators and you will be able to check the share_level attribute.
Hi @lmori and thanks a lot for you answer.
I checked the log of the misp miner and I see share_level set to 'white' so I think those should be good 'candidates' for output.
I'm using minemeld version 0.9.40
and minemeld-misp version 0.1b5
Was a confidence problem...as my output node was a low confidence one... so confidence < 50...
Now it works like a charm...
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!