Comments (8)
@elsif2 Could you please have a look at this? I have also got a similar report during private channels (I didn't have a time to dig into yet)
from intelmq.
The bot downloads the latest reports by checking the past two days for availability and downloads only those that have not been fetched previously.
You can specify the types of reports to download using the types option.
from intelmq.
Thanks @elsif2
I've been attempting to configure the bot to selectively download subsets of scan reports, instead of pulling all the reports for type scan
that can contain 1M plus events. Can it be filtered to download a specific set of reports for example scan_ssl, scan6_ssl, scan_rdpeudp, scan_http, scan6_http etc...
The specific report types I've defined in the configuration don't seem to be filtering as expected.
Could you offer any advice on how to effectively target these report types in the bot's settings?
from intelmq.
What parameters do you have configured for the collector?
Example:
parameters:
types: [scan_ssl, scan6_ssl, scan_rdpeudp, scan_http]
from intelmq.
Yes, that's how I defined them but when i did that way, it did not download any data so I've to apply only scan
in the types field which isn't ideal as it downloads an overwhelming volume of reports.
from intelmq.
The following config only downloads the blocklist
and scan_rdpeudp
types on my system:
parameters:
types: [blocklist,scan_rdpeudp]
What version of IntelMQ are you running?
from intelmq.
intelmqctl --version
3.3.0
ShadowServerAPI-Collector:
bot_id: ShadowServerAPI-Collector
enabled: true
group: Collector
module: intelmq.bots.collectors.shadowserver.collector_reports_api
name: ShadowServerAPI
parameters:
api_key: "$API_KEY_received_from_the_shadowserver_foundation"
bottype: Collector
destination_queues:
_default: [Shadowserver-Parser-queue]
http_header: {}
provider: Shadowserver
rate_limit: 86400
reports: null
secret: $SECRET_received_from_the_shadowserver_foundation"
types: blocklist
run_mode: continuous
Even when the types was set to blocklist, it still downloaded all scan reports, I will do some testing over the next few days and see if any changes
The report field, not sure what values should go in there or it can be left as null
from intelmq.
The types
parameter must be a list:
parameters:
types: [blocklist]
from intelmq.
Related Issues (20)
- Revisit documentation on supported OS versions and packages HOT 2
- deprecate readthedocs.io
- crontab is missing shadowserver update schema script
- Shadowserver parser docs missing part on feedname HOT 2
- intelmq.lib.exceptions.KeyExists HOT 5
- Feature Request: Shadowserver parser setting feed.documentation link HOT 1
- Upgrades error HOT 9
- Can we change it to check for empty "" instead of None. Shadowserver api collector. HOT 5
- documentation build workflow fails in forks
- Initial fetch of shadowserver-schema.json fails even in auto_update mode
- On Windows 10 using Msys2 / Mingw64 - ModuleNotFoundError: No module named 'grp' HOT 3
- intelmq_gen_feeds_conf: yaml.load deprecated HOT 3
- Allow sieve reuse data from the event
- CLI command in ShadowServer API collector/parser to list available report types HOT 2
- pyyaml PendingDeprecationWarning: you should no longer specify 'unsafe' -> test failure
- (doc) Documentation wrong for debian package installation
- Unhardcode paths, add more Unix support. HOT 1
- Shadowserver parser: missing documentation on auto_update
- Introduce strong formatting & linting aka black/ruff
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from intelmq.