MISP integration with SecurityOnion 2.4 #12665
Replies: 4 comments 1 reply
-
Have you tried using the MISP threat intel integration? https://docs.elastic.co/en/integrations/ti_misp |
Beta Was this translation helpful? Give feedback.
-
How do you want to "integrate" MISP into Security Onion? The Github project that you linked to is using MISP's ability to generate Zeek and Suricata rules to take threat intel from MISP and make detection rules for it. That should still work, although the scripts may need a little tweaking to accommodate changes from 2.3 to 2.4. The threat intel integration that cm-ops suggested would ingest the threat intel directly into Elasticsearch, where you could review it in SOC but it wouldn't generate any alerts or anything unless you set up an enrichment pipeline on the back end in Elastic. So, what's your ultimate goal here? |
Beta Was this translation helpful? Give feedback.
-
Hello However the commande curl -- insecure --header "Authorization: Our API Key" works properly and we can see the events and the attributes Also |
Beta Was this translation helpful? Give feedback.
-
Hello please see the configuration we made: |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello
we want to integrate SecurityOnion 2.4 with MISP, we followed the tutorial bellow:
https://github.com/weslambert/securityonion-misp
but we got the attached error:
Are those instructions still valid for securityonion 2.4 ?
Regards.
Beta Was this translation helpful? Give feedback.
All reactions