You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When Entity type is Indicator and Main observable is File with Stix pattern including say more than 1 hash [MD5, SHA1, SHA256, SHA512] , at present all these hashes are added to one refence set "File Hashes"
This is a problem as QRadar has an upper limit on elements (observables) it can store in reference set. By default a reference set in QRadar can have 100k elements for optimal performance , which can be increased but not to the limit which can cater high number of hashes.
Current Workaround
At present no workaround, qradar.py can be modified locally to get it done
Proposed Solution
Instead of creating a single reference set for all file hashes, stream connector should have separate for MD5, SHA1, SHA256…
Use case
When Entity type is Indicator and Main observable is File with Stix pattern including say more than 1 hash [MD5, SHA1, SHA256, SHA512] , at present all these hashes are added to one refence set "File Hashes"
This is a problem as QRadar has an upper limit on elements (observables) it can store in reference set. By default a reference set in QRadar can have 100k elements for optimal performance , which can be increased but not to the limit which can cater high number of hashes.
Current Workaround
At present no workaround, qradar.py can be modified locally to get it done
Proposed Solution
Instead of creating a single reference set for all file hashes, stream connector should have separate for MD5, SHA1, SHA256…
Something like-
OpenCTI - File Hashes (MD5)
OpenCTI - File Hashes (SHA1)
OpenCTI - File Hashes(SHA256)
OpenCTI - File Hashes(SHA512)
The text was updated successfully, but these errors were encountered: