Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Question] Export only NEW observables to EXISTING event in MISP #1899

Closed
mihdim777 opened this issue Mar 26, 2021 · 3 comments
Closed

[Question] Export only NEW observables to EXISTING event in MISP #1899

mihdim777 opened this issue Mar 26, 2021 · 3 comments

Comments

@mihdim777
Copy link

Hello!

Is there any way to export to MISP ONLY new observables (marked as IOC) added AFTER a case was exported to MISP without creating a new event and use PREVIOUS event that was created?

Thank you!

@nadouani
Copy link
Contributor

The MISP export feature is quit simple: we export ALL observable marked as IOC.

@mihdim777
Copy link
Author

Yes, @nadouani . I understood that from the first time. But my question is different. I want to export observables marked as IOC from a case that has been already exported to the same existing event created in MISP.

For example if I export case #1 with 3 observables marked as IOC, it will create event event #1 in MISP.
After that I will add a new observable also marked with IOC to case #1 and I want to export that observable also to MISP to the same event #1, not creating event #2.

Maybe I explained a little bit more clear my question now?

@nadouani
Copy link
Contributor

TheHive MISP connector does the following:

  • create a MISP event if the case is not related to an existing MISP event
  • create an extended MISP event for the case related existing MISP event

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants