intelowlproject/IntelOwl

MISP observable analyzer adjustments

mlodic opened this issue · 6 comments

mlodic commented

We should revision that analyzer:

  • "timeout" in PyMISP should be configurable by the user
  • new option in the search: "published" to get only published event
  • new option in the search: "metadata" to have lighter queries but less data

Reference:
https://github.com/MISP/PyMISP/blob/main/docs/tutorial/Search-FullOverview.ipynb

Hi, I would like to work on this issue @mlodic

mlodic commented

hey, this is an urgent feature to add: if you get the time to try to work on it right now you can pick up, otherwise please select another issue to start with IntelOwl :) thank you for your understanding

hi wanted to contribute for this issue.
could you please assign.
also while trying this out, I'm not sure what should be and misp-url in misp analyzer while configuring it.
I setted up misp-docker and launched http://localhost:8080/ and setted this as misp-url and with api_key but doesnt works.
could you please guide over it.

if you have both intelowl and misp in the same machine in 2 different docker networks, they just cannot communicate

g4ze commented

Hellou! @mlodic I'll look into this one