TheHive-Project / TheHive

TheHive: a Scalable, Open Source and Free Security Incident Response Platform
https://thehive-project.org
GNU Affero General Public License v3.0
3.28k stars 604 forks source link

Not getting all the alerts from MISP #2483

Open MU-03 opened 3 months ago

MU-03 commented 3 months ago

Request Type

Bug

Work Environment

Question Answer
OS version (server) Ubuntu
OS version (client) Ubuntu
Virtualized Env. True / False
Dedicated RAM 16 GB
vCPU 8
TheHive version / git hash 4.1.24-1
Package Type From source
Database Cassandra
Index type Elasticsearch
Browser type & version Firefox

Problem Description

After Integrating TheHive with MISP, not getting all the events from MISP as alerts in TheHive

Steps to Reproduce

  1. In MISP there are 5000 events
  2. Integrated MISP with TheHive
  3. Restarted the hive and wait for hours

    Possible Solutions

    On Hive UI im only getting alerts of around 30 alerts from MISP , I have set the time interval in application.conf as 1 minute .