-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
connector state null #61
Comments
Do you have anything that indicates that it isn't working? This is an enrichment connector, so it will only perform work when a new entity is ingested into your platform. Alternatively, you can enrich an entity manually (see the documentation in the Usage section). The state field is not used for enrichment connectors. I believe they are only used by stream connectors, possibly other types. I'll take this cause confusion into consideration when updating the manual. |
You most likely have a self-signed certificate in OpenSearch (which is the norm). You will have to skip TLS verification. See important settings in the documentation. The env. var. would be |
Your last screenshot is not an error. Have a look in the documentation: As for your errors in the previous runs, please provide information about what they say, and I will try to help. |
It appears that you are enriching indicators. As I pointed out earlier with the references to the documentation, enriching indicators only work if those indicators have relationships to observables, as there is no direct STIX indicator pattern support. The only workaround I can offer for now, is using automation to create these relationships automatically.
It is if there is nothing for the connector to do, or if the indicator was not found in Wazuh. It only creates STIX objects when the search is performed, and results are found. |
Incidents are created depending on your configuration. See the documentation on the topic.
This is an identity of type system. You'll find this under "systems" in OpenCTI, and linked to in all incidents. |
can anyone help me? my connector doesn't working
is there something wrong with my configuration?
The text was updated successfully, but these errors were encountered: