Skip to content

Instantly share code, notes, and snippets.

# ==================================
# === MISP Threat Intelligence Match ===
# ==================================
#
# Detects messages to which the MISP module has added a match flag.
# Creates a new correlated event.
#
# Vstupná správa vyzerá napr.:
# Oct 10 16:18:02 localhost CEF:0|Security|... src=10.0.0.1 ... misp_src_hit=true misp_src_id=42 alert_priority=high
#