ElasticsearchFeed
Fetches indicators stored in an Elasticsearch database.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- FeedElasticsearch
Configuration parameters
- url — Server URL (required)
- credentials — Name (see ?->Authentication)
- client_type — Client type
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- feed_type — Feed Type
- feed — Fetch indicators
- fetch_time — First Fetch Time
- fetch_limit — Fetch Limit
- feedReputation — Indicator Reputation
- feedReliability — Source Reliability (required)
- tlp_color — Traffic Light Protocol Color
- feedExpirationPolicy —
- feedExpirationInterval —
- feedFetchInterval — Feed Fetch Interval
- feedTags — Tags
- feedBypassExclusionList — Bypass exclusion list
- src_val — Indicator Value Field
- src_type — Indicator Type Field
- default_type — Indicator Type
- fetch_index — Index from Which To Fetch Indicators
- time_method — Time Field Type
- time_field — Index Time Field
- es_query — Query
- feedIncremental — Incremental Feed
- enrichmentExcluded — Enrichment Excluded
Commands (1)
- es-get-indicators — Gets indicators available in the configured Elasticsearch database.