Closed schimpy closed 1 year ago
Hello, thank you for using MISP42. I will try to reproduce error on my side. Which version do you use? also could you check error messages in SPLUNK_HOME/var/log/splunk/misp_alert_create_event_modalert.log?
I have been testing the update of an existing event using the basic /app/misp42splunk/misp_alert_create_event dashboard. It works for me.
Hi, thank you for this feedback and for using misp42. I have just pushed back new 4.2.0 . If you have time to double-check you have no issue with it, thanks in advance
Hello folks.
I am facing an issue while adding IOCs to an existing event. I am using "sendalert" command with "param.eventid" set from previous results and I receive following error:
Error in 'sendalert' command: Alert script returned error code 5.
Details:
SPL (abbreviated):
How the SPL should behave:
How the SPL behaves now:
I suspect param.eventid not working properly. I also tried to paste in both the event ID and event UUID as it is (not using $result.event_uuid$) and it is not working as well. I also tried the dashboard to test this, also failing with the same error code.
Have anyone encounter such issue? What is the best way to update an existing event?