Skip to content

IRIS alert context does not work correctly #1348

Closed Locked Answered by malinkinsa
Areopagit asked this question in Q&A
Discussion options

You must be logged in to vote

@Areopagit hello.
There was an issue with nested JSON within the document. To fix it, I borrowed the approach used in TheHive's alerter. I checked both options - couldn't replicate the problem after the fix. Also expanded the tests.

Regarding IOC and IPs, the problem lies in the fact that your IP data is formatted as a list [] and therefore doesn't pass the IRIS validator. Ideally, you should parse it into a separate field and request that.

@jertel
PR ready, any feedback is welcome.

Replies: 5 comments 10 replies

Comment options

You must be logged in to vote
1 reply
@Areopagit
Comment options

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
5 replies
@malinkinsa
Comment options

@malinkinsa
Comment options

@malinkinsa
Comment options

@malinkinsa
Comment options

@Areopagit
Comment options

Comment options

You must be logged in to vote
3 replies
@malinkinsa
Comment options

@Areopagit
Comment options

@malinkinsa
Comment options

Comment options

You must be logged in to vote
1 reply
@Areopagit
Comment options

Answer selected by Areopagit
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants