I have a few Threat Intelligence data that have Use-Cases applied to them but I'm trying to filter out blocked events, for example - say an asset was attempting to communicate with a malicious site and it was blocked by the proxy or firewall. Do I tune the use-case search itself or modify the Threat Intelligence datamodel?
All suggestions are appreciated.
Hi @gcusello ,
Thanks for the feedback, let me post an example of the search I'm attempting to modify or maybe in another case modify the datamodel.
Hi @oylkm,
I suppose that you're speaking about ES.
Anyway in some projects I customized both Datamodels and Use cases, it depends on the customization:
if the difference is only a new field to add to theDataModel to use in search the DataModel customization is the quicker way, otherwise you could clone and modify a Use Case (never modify the original Use Case!).
Speaking about Threat Intelligence, maybe you should modify not the Threat Intelligence Datamodel, but the scheduled search used to populate the DataModel, But it isn't a job so easy and you need a deep knowledge about ES in general and threat Intelligence DataModel in deep!
Ciao.
Giuseppe