MISP / MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Home Page:https://www.misp-project.org/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Feature Request: Add last modified timestamp to warninglists

Wachizungu opened this issue · comments

Is your feature request related to a problem? Please describe.

We have a filtered dataset of indicators from MISP in our SIEM, which also filters using MISP warninglists.
The filter processing is quite heavy, so we would prefer not to run the entire extract every day.

To keep the data sets as consistent as possible, we need to re-apply warninglist filtering when a warninglist's entries are updated.
We can do this by keeping track of the warninglist versions, but it's not very elegant as it requires us to keep track of the warninglist versions.

Describe the solution you'd like

Have a last change timestamp for warninglists, which is queryable via API. That way we can have logic if any of the enabled warninglists changed in last x time, trigger re-filtering on warninglists.

Describe alternatives you've considered

Keep track of the warninglist versions.

Additional context

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct