Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document usage of data filtering strategy #67

Open
iglocska opened this issue Oct 27, 2017 · 1 comment
Open

Document usage of data filtering strategy #67

iglocska opened this issue Oct 27, 2017 · 1 comment
Labels
help wanted This is an issue that community can help with S: stale Status: stale. This issue has had no activity in a long time, it may not be relevant anymore T: enhancement Type: enhancement. This issue seeks an improvement of an existing feature

Comments

@iglocska
Copy link
Member

Quote from a mail, this but better explained:

"our mantra is, keep your data for correlation and exclude it from the exports. What I'd suggest:

a. Set an automatic tag for your feed (such as "expireMeInAMonth") - these tags will be automatically applied to all events coming from the feed hereafter
b. When exporting data from MISP, for example for your SIEM/NIDS/etc use the following rules:

  • 1x full data set, but exclude everything tagged "expireMeInAMonth"
  • 1x the data set carrying the "expireMeInAMonth" tag, but with the "last":"30d" parameter set
    c. Feed both data sets to your tools

This will get you all your regular data + the past 30 day's worth of data from the feed."

@enjeck enjeck added help wanted This is an issue that community can help with S: stale Status: stale. This issue has had no activity in a long time, it may not be relevant anymore T: enhancement Type: enhancement. This issue seeks an improvement of an existing feature labels Nov 17, 2020
@Wachizungu
Copy link
Contributor

I'm guessing this would translate to using the decaying mechanism now?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
help wanted This is an issue that community can help with S: stale Status: stale. This issue has had no activity in a long time, it may not be relevant anymore T: enhancement Type: enhancement. This issue seeks an improvement of an existing feature
Projects
None yet
Development

No branches or pull requests

3 participants