Skip to content

Alerts Actions suggestion - AbuseIPDB Search #2541

Locked Answered by weslambert
greatapoc asked this question in Ideas
Discussion options

You must be logged in to vote

Hi @greatapoc ,

Thanks for the suggestion! In the meantime, you can actually copy /opt/so/saltstack/default/salt/soc/files/soc/alerts.actions.json to /opt/so/saltstack/local/salt/soc/files/soc/alerts.actions.json and modify the entries there to include a lookup for AbuseIPDB.

Like so:

{ "name": "actionAbuseIPDB", "description": "actionAbuseIPDBHelp", "icon": "fa-external-link-alt", "target": "_blank","links": [ "https://www.abuseipdb.com/check/{value}"

Then restart SOC with so-soc-restart

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@greatapoc
Comment options

@greatapoc
Comment options

@weslambert
Comment options

@greatapoc
Comment options

Answer selected by TOoSmOotH
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Ideas
Labels
None yet
2 participants