All Apps and Add-ons

Splunk MISP42 sighting: How to update the sighting of an attribute in connected MISP instance?

schimpy
New Member

Hello folks,

Has anyone of you made it work that you somehow update the sighting of an attribute in connected MISP instance?

I have my MISP integrated to Splunk, IoC are being downloaded to TI framework. Based on this some correlation searches that are scheduled, TI-based notables triggers

I am looking for a way how to get the feedback about TP/FP back to MISP.

I am using MISP42Splunk app, which has an adaptive response action "Alert for sighting MISP attribute(s)"  but I cannot make it work.

I was also trying to do it via some in-build MISP command without any success.

Do you guy have implemented this feature of do you know some way to do it?

Thanks!

Labels (3)
Tags (2)
0 Karma

riccardo_spl
Explorer

Never used this adaptive response type, did you get any success?

0 Karma
Get Updates on the Splunk Community!

CX Day is Coming!

Customer Experience (CX) Day is on October 7th!! We're so excited to bring back another day full of wonderful ...

Strengthen Your Future: A Look Back at Splunk 10 Innovations and .conf25 Highlights!

The Big One: Splunk 10 is Here!  The moment many of you have been waiting for has arrived! We are thrilled to ...

Now Offering the AI Assistant Usage Dashboard in Cloud Monitoring Console

Today, we’re excited to announce the release of a brand new AI assistant usage dashboard in Cloud Monitoring ...