17.2. MISP threat feed configuration

This section describes how to initialize and configure MISP settings.

Navigate to the MISP tab of the External Feed Handler MC component. To modify the parameters, check the Enable option to use MISP-based filtering and adjust the parameters as needed.

External Feed Handler component MISP settings

Figure 17.3. External Feed Handler component MISP settings

  • URL: URL to MISP server where API calls can be made.

  • API key: the API key generated by the MISP server.

  • Complete redownload hours: specific amount of time, measured in hours, that elapses between downloading the entire database. At intervals specified in Update interval, only those events are downloaded that have been added to the database since the last check. Therefore, to ensure that there are no events that have not been downloaded, it is worth downloading the entire database at some point.

  • Update interval: if the Global Update interval is not apropriet, uncheck the Use global update interval to adjust the parameters as needed.