Open chrisanag1985 opened 2 years ago
I fixed it by adding in the buildSTIXAttributes.py
if type_ == "ip-src":
....
addr.category = "ipv4-addr"
....
elif type_ == "ip-dst":
....
addr.category = "ipv4-addr"
....
#also i edited the followings
elif type_ == "domain":
....
dn.type_ = "FQDN"
....
elif type_ in ["url","uri"]:
.....
url.type_ = "URL"
.....
can we add it to the main branch?
Hello. when converting an MISPEvent to STIX when it finds
ip-src
orip-dst
it doesn't put the attributecategory="ipv4-addr"
, so when the SIEM QRadar tries to obtain IP STIX Events it doesn't understand it so it skips these type of events. When i manually add thecategory
it can understand them and consumes them.thank you.