Skip to content
Discussion options

You must be logged in to vote

This is PyMISP pythonify, not MISP refusing the event. In 2.5.34, MISPGalaxyCluster.from_dict() errors when default is true and distribution is present. Default galaxy clusters (MITRE tags and the rest) are not something you attach a distribution to. The REST payload still includes distribution on those objects, so pythonify=True blows up on search / add / update after tag().

pythonify=False works because you never build MISPGalaxyCluster.

Until PyMISP pops those fields on inbound default clusters instead of raising:

def _strip_default_cluster_distribution(d):
    if not isinstance(d, dict):
        return d
    # walk Event -> Galaxy -> GalaxyCluster (shape varies)
    ...

or catch NewGa…

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
1 reply
@mhpchaves
Comment options

Answer selected by mhpchaves
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants