OpenCTI-Platform / connectors

OpenCTI Connectors
https://www.opencti.io
Apache License 2.0
380 stars 412 forks source link

[QRadar] Bad default QRadar configuration #2585

Closed Lhorus6 closed 2 months ago

Lhorus6 commented 2 months ago

Description

We had the wrong default URL on our Github. With the current URL, we can only create data (so send IOCs) but not update.

README and conf file to modify

image

Lhorus6 commented 2 months ago

The suggested endpoint is deprecated. So we should see how to do it while always using the endpoint "reference_data_collections".

See https://github.com/OpenCTI-Platform/connectors/issues/2124

Maybe we should use different endpoints to manage the update

Lhorus6 commented 2 months ago

Additional note (for the record):

With current version of code, new endpoint cannot be used as it does not have same parameters, e.g.: