Skip to content

Commit 5b4f408

Browse files
committed
Added search to populate opencti_lookup
1 parent af5d742 commit 5b4f408

File tree

1 file changed

+19
-0
lines changed

1 file changed

+19
-0
lines changed

TA-opencti-add-on/default/savedsearches.conf

Lines changed: 19 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,25 @@ alert.suppress = 0
3535
alert.track = 0
3636
action.summary_index = 0
3737

38+
[Update OpenCTI Lookup]
39+
search = search `opencti_index` sourcetype="opencti:indicator" (event="create" OR event="update" OR event="delete") earliest=-15m latest=now \
40+
| eval delete_flag=if(event="delete", "true", null()) \
41+
| table id, _key, created, created_at, created_by, created_by_ref, description, detection, indicator_types, input_name, lang, main_observable_type, markings, modified, name, object_marking_refs, pattern, pattern_type, revoked, score, spec_version, type, updated_at, valid_from, valid_until, value, delete_flag \
42+
| append [ | inputlookup opencti_lookup ] \
43+
| stats latest(*) as * by id \
44+
| where isnull(delete_flag) \
45+
| fields - delete_flag \
46+
| outputlookup opencti_lookup
47+
description = Updates the opencti_lookup lookup with new and updated indicators, while flagging deleted ones.
48+
schedule = */5 * * * *
49+
enabled = 1
50+
dispatch.earliest_time = -15m
51+
dispatch.latest_time = now
52+
cron_schedule = */5 * * * *
53+
alert.suppress = 0
54+
alert.track = 0
55+
action.summary_index = 0
56+
3857
[Update OpenCTI Threat Intelligence]
3958
search = search index=opencti_stream sourcetype="opencti:indicator" (event="create" OR event="update" OR event="delete") earliest=-15m latest=now \
4059
| eval delete_flag=if(event="delete", "true", null()) \

0 commit comments

Comments
 (0)