pulling in Alienvault OTX pulses into Security Onion 2 not working #1647
Replies: 3 comments 1 reply
-
|
Those docs have not been updated yet. Let me know if you figure it out and we can update the documentation. |
Beta Was this translation helpful? Give feedback.
-
|
Hi Mike, yes i found a workaround and it worked. First, I modified some paths in the securityonion-otx bash file (attached the modified one , make sure to remove .txt ext). Now, bro-otx.py script will work properly and IOCs will be pulled from Alienvault, however I still need to know the path where I should save the otx.dat file for Security Onion to match the IOCs inside this file? please advise |
Beta Was this translation helpful? Give feedback.
-
|
I saved the otx.dat file to /opt/so/saltstack/local/salt/zeek/policy/intel but still not getting an Intel hit when testing |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello Gents,
I followed the instruction on https://docs.securityonion.net/en/2.3/alienvault-otx.html?highlight=alienvault#installation to pull pulses to Security Onion 2.3.1 but it is not working. It seems there has been a change in some directories in Security Onion 2. Any advice please?
Beta Was this translation helpful? Give feedback.
All reactions