Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ignored MISP events are no longer visible and cannot be imported #107

Closed
saadkadhi opened this issue Feb 4, 2017 · 1 comment
Closed
Assignees
Milestone

Comments

@saadkadhi
Copy link
Contributor

Request Type

Feature Request

Work Environment

Question Answer
OS version (server) Ubuntu
OS version (client) Ubuntu
TheHive version / git hash 2.10.0
Package Type Binary
Browser type & version Chrome 56

Problem Description

If an analyst discards a MISP event or ignores an update by mistake, they cannot undo their action. TheHive must make it possible to search or see ignored/discarded MISP events and create cases out of them.

There's another use case for such a feature. An analyst may get a report on suspicious activity related to a MISP event hours or days after they've seen it and ignored it, believing it is not of concern.

Or take for instance the 1st time when TheHive is connected to a MISP server. The analyst may get tons of events and they would sift through them hastily only to realize that they've been too quick on the ignore button.

Possible Solutions

Add the ability to view and search ignored MISP events and make cases out of them if needed.

@saadkadhi saadkadhi added this to the 2.11.0 milestone Feb 4, 2017
@nadouani
Copy link
Contributor

This issue has also been fixed by #86

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants