-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add MISP Alerter #2126
base: master
Are you sure you want to change the base?
Add MISP Alerter #2126
Conversation
Hi @Qmando , Is there anything I can do to improve this, or make this more acceptable? Thanks! |
Hi, im trying to use this alerter to upload an incident on my MISP server, but my rule keeps showing 1 alert sent even if there is nothing new in my MISP server. Here is my rule log: My rule .yaml: es_host: x.x.x.x es_port: 9200 name: MyRule type: any index: myindex filter: alert: mispalerter misp_alert_config: misp_attribute_data_mapping: Im new at this so sorry if im missing something obvious. I use the same configuration with the email alerter and works fine. Thanks |
Hi @MarkDevelo , it's been a minute since I've looked at this, so I will test again and let you know. |
Thanks @weslambert , if it helps in the MISP logs i can see the elastalert successful authentication using the API key, in the "change" column it shows "HTTP method: GET" all HTTP methods are "GET" the "target" is the only one that changes : |
■README.md ■ docs/source/ruletypes.rst |
I haven't tested this recently -- did this work for you, @nsano-rururu ? |
I haven't moved it yet. |
Travis CI build failed |
Yes, I will have a look at it tonight -- will probably end up re-writing some of it anyway. Thanks! |
Any way you could push this PR to https://github.com/jertel/elastalert2 ? |
@nsano-rururu, sure thing -- will do so when I get a chance. |
Here are some things to keep in mind when making a pull request to elastalert2. Please note that the source code structure of the alert is now different from the original yelp / elastalert. Structure of related files and source code
|
Understood, thanks! |
Similar to
HiveAlerter
, allows the user to create events within MISP from Elastalert matches using theMISPAlerter
class, and alert type ofmispalerter
.Rule format should be similar to the following: