TheHive-Project / TheHive

TheHive: a Scalable, Open Source and Free Security Incident Response Platform
https://thehive-project.org
GNU Affero General Public License v3.0
3.39k stars 617 forks source link

Problem in list alerts in thehive4 [Question] #2430

Open romarito90 opened 1 year ago

romarito90 commented 1 year ago

Request Type

Question

How I can load in real time the alerts in the alert page in thehive? Dont syncronize the number of alerts in real time with the alerts shown in the alerts page.

alerts

Work Environment

Question Answer
OS version (server) Ubuntu 22
OS version (client)
Virtualized Env. True / False
Dedicated RAM XX GB
vCPU 4
TheHive version / git hash 4.1.24, hash of the commit
Package Type DEB
Database Cassandra
Index type Elasticsearch
Attachments storage Local
Browser type & version Firefox

Question

How I can improve the performance of list of alerts in thehive4, because when I integrate the wazuh and thehive integration, I receive the alerts from wazuh, I see the number of alerts coming form wazuh in real time, but the alerts dont appears in the alerts page of the thehive. The alerts are very slow in appears in the alerts page. the number of alerts and the alerts shown is different and sometimes the alerts dont appears.

I'm using the integration script shown in this page

https://wazuh.com/blog/using-wazuh-and-thehive-for-threat-protection-and-incident-response/

this is the same

https://github.com/crow1011/wazuh2thehive