You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
In order to support IoC expiration for Recorded Future, following need to be added to the package:
Path forward:
The current source indices should contain all IoC ingesting every interval. In other words, we need to maintain duplicate IoCs inside source indices. This needs removal of current fingerprint processor
Destination indices should only contain latest IoCs since the last time the transform ran and they are created using latest transform i.e, unique key with combination of fields event.dataset, threat.indicator.type, and Name
Transform also needs to define a retention policy for it to delete old IoCs.
The text was updated successfully, but these errors were encountered:
In order to support IoC expiration for Recorded Future, following need to be added to the package:
Path forward:
fingerprint
processorevent.dataset
,threat.indicator.type
, andName
The text was updated successfully, but these errors were encountered: