PaloAltoNetworks / minemeld

Main MineMeld documentation repo
379 stars 64 forks source link

Carbon Black Feed Not Showing Indicators in Report #52

Closed ghost closed 4 years ago

ghost commented 4 years ago

Describe the bug

When using the v=carbonblack option to generate a feed into the correct format for Carbon Black Response no indicators are included from the output node. Tried with multiple output types and with feeds within only 5-10 indicators and feeds with 000's of indicators. None appear in the list.

Expected behavior

If I remove the v=carbonblack parameter I see a list of all the indicators are normal so assuming this feature has a bug.

Current behavior

As above.

Possible solution

Not sure.

Steps to reproduce

  1. Create a output node that has some domains or IPv4 indicators
  2. Browse to the node URL and append ?v=carbonblack to the URL
  3. Scroll to bottom of page (past base64 encoded images) and look to see if anything is populated within theiocs { } section.

Screenshots

image

Context

Your Environment

welcome[bot] commented 4 years ago

:tada: Thanks for opening your first issue here! Welcome to the community!

xhoms commented 4 years ago

Thanks @mpgough for reporting the issue. CarbonBlack output feed only supports IPv4, md5 and domain (not URL!) indicator types. Could you, please, double-check the indicators you're missing are of domain type instead of url?

ghost commented 4 years ago

Issues on my side. Please ignore.