Hello,
I would like to request guidance on how to create a correlation search based on data provided by SANS Threat Intelligence from https://isc.sans.edu/block.txt
The malicious IPs from "block.txt" are updated regularly. How can my correlation search track that change in real-time? What queries to use?
Notes: The SANS Threat Intel has already been enabled.
consider using the PAVO Getwatchlist add-on, then you can do this:
Or for performance, schedule the search every 30min, and pipe it to a lookup. then run your search using the lookup for matches.
consider using the PAVO Getwatchlist add-on, then you can do this:
Or for performance, schedule the search every 30min, and pipe it to a lookup. then run your search using the lookup for matches.