MISP Integration

Ali Salem Panah 40 Reputation points
2024-12-02T14:44:28.58+00:00

Hi Technical Team,

Recently, I attempted to integrate MISP with Sentinel. Below are the steps I followed based on this link

  1. Installation Part :
    1. steps 1 - 5
  2. Grant the necessary permissions
    1. steps 1- 8 (using the Upload Indicators API)
  3. Threat intelligence data connector
    1. steps 1 - 5
  4. Azure Function
    1. steps 2 - 11
  5. MISP
    1. API key

Everything appears to be working properly, as shown in the screenshot, but the feeds are not ingesting into Sentinell Screenshot 2024-12-02 at 15.22.31

Screenshot 2024-12-02 at 15.23.38

Microsoft Security Microsoft Sentinel
{count} votes

Accepted answer
  1. Akhilesh Vallamkonda 15,320 Reputation points Microsoft External Staff Moderator
    2024-12-10T03:42:37.9133333+00:00

    Hi @Ali Salem Panah

    I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others ", I'll repost your solution in case you'd like to "Accept " the answer.Issue:

    integrated MISP with Sentinel the feeds are not ingesting into Sentinell

    Solution:

    You have resolved the issue by modified your script by updating the tenant ID, client security, and other information

    The other side about the documents, we don't have any documentation or a direct partnership with this ISV at the moment. For help with integrating their solution with Microsoft Sentinel, we suggest contacting Wing Security.

    If you have any other questions or are still running into more issues, please let me know. Thank you again for your time and patience throughout this issue.

    Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

    1 person found this answer helpful.
    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.