-
Notifications
You must be signed in to change notification settings - Fork 522
ti_misp: add daily refetch option to threat attributes #16491
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
ti_misp: add daily refetch option to threat attributes #16491
Conversation
|
Pinging @elastic/security-service-integrations (Team:Security-Service Integrations) |
🚀 Benchmarks reportTo see the full report comment with |
chrisberkhout
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The daily refetch seems good, but setting a 24-hour expiration is confusing.
Since we already have a latest transform, can't we just make sure the transform picks up the latest version of each item (this may require adding an ingest time or something) and leave the decay score and decayed at the same?
Things still get updated as their decay info changes in MISP, and we have the same rules as usual for orphans.
I have a doubt with that approach, the idea for forcing a 24-hour expiration for ingested indicators with this new daily refresh mode, is that we make sure that indicators that have been decayed by MISP are dropped from the destination indices every day. If we leave the |
💚 Build Succeeded
History
|
Proposed commit message
Added a new configuration option
daily_refetchthat, when enabled:Checklist
changelog.ymlfile.Related issues
Screenshots