FortiSIEM Discussions
baibhav
New Contributor

Custom Malware IP Threat Intelligence Integration with FortiSIEM

Team,

 

We are pull STIX Taxii threat feeds from backend with CURL Command but when configured in FortiSIEM console with java plugin(as per the oneline document) 

https://help.fortinet.com/fsiem/5-0-1/Online-Help/HTML5_Help/Importing_malware_ip_information.htm#Cu....

 

But I get error as below , please help here.  I imported HTTPS certificate too. 

[2023-10-13T18:37:00.528+0530] [glassfish 5.1] [WARNING] [] [com.accelops.service.threatfeed.impl.StixMalwareIPUpdateService] [tid: _ThreadID=305 _ThreadName=PHScheduler_Worker-22] [timeMillis: 1697202420528] [levelValue: 900] [[
Failed to handle STIX response caused by: org.mitre.taxii.messages.xml11.StatusMessage cannot be cast to org.mitre.taxii.messages.xml11.PollResponse. Response: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<taxii_11:Status_Message status_type="FAILURE" in_response_to="urn:uuid:a398cff3-37f0-498e-8d23-3bb5e4e4c83f" message_id="0" xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" xmlns:xmldsig="http://www.w3.org/2000/09/xmldsig#">
<taxii_11:Message>Set-Cookie: JSESSIONID=2CD06BFB65CFA340D63427C456FD205F; Path=/mss-cyberthreatintel-service; HttpOnly; Secure;&#13;
CTI-Application-Request-Id: ee7e4b56-9e13-4019-a45d-7e73d7147b8d&#13;
Allow: GET&#13;
X-Content-Type-Options: nosniff&#13;
X-XSS-Protection: 1; mode=block&#13;
Cache-Control: no-cache, no-store, max-age=0, must-revalidate&#13;
Pragma: no-cache&#13;
Expires: 0&#13;
X-Frame-Options: DENY&#13;
Content-Type: application/xml;charset=UTF-8&#13;
Content-Length: 168&#13;
Date: Fri, 13 Oct 2023 13:07:00 GMT&#13;
Access-Control-Allow-Credentials: true&#13;
Access-Control-Allow-Methods: POST,GET&#13;
Access-Control-Max-Age: 3600&#13;
Access-Control-Allow-Headers: x-auth-token,Origin,Accept,X-Requested-With,Content-Type,Access-Control-Request-Method,Access-Control-Request-Headers,Authorization,source,userType,time-zone&#13;
X-Frame-Options: SAMEORIGIN&#13;
Cache-Control: no-cache&#13;
X-Robots-Tag: noindex,nofollow&#13;

3 REPLIES 3
baibhav
New Contributor

FortiSIEM Version 6.7. 

FSM_FTNT
Staff
Staff

@baibhav in 7.0 we introduced a python based framework for threat intel integration, it should help with integrations.

 

Are you trying to integrate with a public feed?

Goutham_FTNT
Staff
Staff

Hi Baibhav,

Can you provide me the complete version ? 6.7.x ?
Also the host server is external or internal to your env ? (I understand you are using https hence imported the cert)
Is it possible for you to provide the curl response from backend where it works ? (You can mask the data to limit just 1 or 2 )
I suspect the issue with plugin hence require the exact version to check this 

Regards,
Goutham

Announcements

Welcome to your new Fortinet Community!

You'll find your previous forum posts under "Forums"