Hi David
I've added quite a few URL based intelligence feeds which are typically a web page of IP's however, as my original post yes I'm stuck as I get parsing errors.
I've followed the instructions.
Here's the guide on how to add a webpage as a threat intel source for ES :
I've tried the following to extract the fields.
And listed the fields
I've tried using regular expressions to extract the fields, I've also tried to use a separator.
The download feed consists of 8 fields seperated by '|' symbol which start at line 155 in the web page.
The web page consists of html and each line consisting of the six fields has the following html
The fields are:
Eight field is optional.
I've tested listing the fields in the notation as documented:
Checking the threat management log I see parsing failure.
... View more