You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Feb 2, 2024. It is now read-only.
All IoC's are pulling without any changes to base config from misp.tlpWhiteEvent.
When using that prototype, I would expect the miner to only pull in events / IoC's that are tagged as "tlp:white" but it's not filtering (all IoC's are ingested).
I've also tried filtering by custom tags I have in MISP but then it won't pull anything.
Please let me know if I'm missing something or how I can fix it.
Thanks
Little clue, checked on MISP in /var/log/apache2/misp-dashboard.local_access.log
When u do a pull manually from minemeld, it outputs correctly the event IDs that had the tag you settled on minemeld with filter tags: 55 for example. So basically the request seems correct but doesn't go further.
All IoC's are pulling without any changes to base config from misp.tlpWhiteEvent.
When using that prototype, I would expect the miner to only pull in events / IoC's that are tagged as "tlp:white" but it's not filtering (all IoC's are ingested).
I've also tried filtering by custom tags I have in MISP but then it won't pull anything.
Please let me know if I'm missing something or how I can fix it.
Thanks
My stack...
MISP Extension - 2.4.96b1
MISP Docker - https://github.com/MISP/docker-misp
MineMeld Docker - https://live.paloaltonetworks.com/t5/MineMeld-Articles/Running-MineMeld-using-Docker/ta-p/289062
The text was updated successfully, but these errors were encountered: