Closed JohanPhom closed 10 months ago
Issues is probably not related to QRadar. I managed to get data ingested into QRadar using other XML files in STIX format from other sources. I believe problem is probably because MISP is generating a STIX format non understandable for QRadar.
Hi everyone,
I am trying to ingest some IOC in QRadar from OpenTaxii in Docker container. Here is what I managed to do:
However when I pull the data with 'Poll Now', I don't receive any data. I know the timestamp matters when QRadar pulls data so I tried to create an fresh IOC event (from MISP), and push it to the taxii server before pulling it from QRadar, but nothing.
I used tcpdump to check what the taxii server answers, and I can see the server sending the IOC to QRadar, so it seems that QRadar doesn't understand the data. When pulling from QRadar, I configured it to use TAXII 1.x.
Here is my configuration file for the taxii server:
Regarding the services I have the exact default configuration from data-configuration.yml
Any help would be appreciated