Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Request/Help needed #98

Open
WebBotMaster opened this issue Jun 29, 2021 · 0 comments
Open

Request/Help needed #98

WebBotMaster opened this issue Jun 29, 2021 · 0 comments

Comments

@WebBotMaster
Copy link

Hey, basically more a request then an issue, but I can't find a better way to contact you then through a github issue.
Basically I want to do the following:
MISP[Server1] -> OpenTaxii[Server2] -> Multiple different SIEM's[multiple external devices].
My Idea is that nowadays probably every SIEM should have a STIX / TAXII import available, hence the setup.
I was wondering if your implementation could serve this purpose. Of course I saw the "push_published_to_taxii" skript and also the "install-remote-server.sh" skript.
Is it possible to install the OpenTaxii Server external with gunicorn and then use the "push-published-to-taxii" skript to
push MISP Events to the production server ? Is this the best way to accomplish my objective ?
The MISP Server is fully setup but maybe you got a better option to export MISP Events into SIEM's ? Got a working Skript to export MISP to QRadar, but I would prefer not to make a custom skript for every available SIEM out there...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant