Team,
We are pull STIX Taxii threat feeds from backend with CURL Command but when configured in FortiSIEM console with java plugin(as per the oneline document)
But I get error as below , please help here. I imported HTTPS certificate too.
[2023-10-13T18:37:00.528+0530] [glassfish 5.1] [WARNING] [] [com.accelops.service.threatfeed.impl.StixMalwareIPUpdateService] [tid: _ThreadID=305 _ThreadName=PHScheduler_Worker-22] [timeMillis: 1697202420528] [levelValue: 900] [[
Failed to handle STIX response caused by: org.mitre.taxii.messages.xml11.StatusMessage cannot be cast to org.mitre.taxii.messages.xml11.PollResponse. Response: <?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<taxii_11:Status_Message status_type="FAILURE" in_response_to="urn:uuid:a398cff3-37f0-498e-8d23-3bb5e4e4c83f" message_id="0" xmlns:taxii_11="http://taxii.mitre.org/messages/taxii_xml_binding-1.1" xmlns:xmldsig="http://www.w3.org/2000/09/xmldsig#">
<taxii_11:Message>Set-Cookie: JSESSIONID=2CD06BFB65CFA340D63427C456FD205F; Path=/mss-cyberthreatintel-service; HttpOnly; Secure;
CTI-Application-Request-Id: ee7e4b56-9e13-4019-a45d-7e73d7147b8d
Allow: GET
X-Content-Type-Options: nosniff
X-XSS-Protection: 1; mode=block
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
Pragma: no-cache
Expires: 0
X-Frame-Options: DENY
Content-Type: application/xml;charset=UTF-8
Content-Length: 168
Date: Fri, 13 Oct 2023 13:07:00 GMT
Access-Control-Allow-Credentials: true
Access-Control-Allow-Methods: POST,GET
Access-Control-Max-Age: 3600
Access-Control-Allow-Headers: x-auth-token,Origin,Accept,X-Requested-With,Content-Type,Access-Control-Request-Method,Access-Control-Request-Headers,Authorization,source,userType,time-zone
X-Frame-Options: SAMEORIGIN
Cache-Control: no-cache
X-Robots-Tag: noindex,nofollow
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
FortiSIEM Version 6.7.
@baibhav in 7.0 we introduced a python based framework for threat intel integration, it should help with integrations.
Are you trying to integrate with a public feed?
Hi Baibhav,
Can you provide me the complete version ? 6.7.x ?
Also the host server is external or internal to your env ? (I understand you are using https hence imported the cert)
Is it possible for you to provide the curl response from backend where it works ? (You can mask the data to limit just 1 or 2 )
I suspect the issue with plugin hence require the exact version to check this
Regards,
Goutham
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.