misp_event_reports publisher
blackstork/misp, v1.0.0
Description #
Publishes a Markdown document as an Event Report attached to an existing MISP event.
Installation #
blackstork configuration block manually.To use the misp_event_reports publisher locally via blackstork-cli, you must declare the blackstork/misp plugin as a dependency in your global configuration block.
blackstork {
plugin_versions = {
"blackstork/misp" = ">= v1.0.0"
}
}
After declaring the dependency, execute blackstork-cli install to fetch the plugin. See Configuration for details.
Supported Formatters #
This publisher supports the delivery of documents formatted by the following formatters:
md
Use format_ref in the publish block to reference a root-level format block or a format block in the current document. References to in-document blocks require the document. prefix.
Configuration #
This publisher accepts the following configuration arguments within a config publish misp_event_reports block:
config publish misp_event_reports {
# misp api key
#
# Required string.
# Must be non-empty
#
# For example:
api_key = "some string"
# misp base url
#
# Required string.
# Must be non-empty
#
# For example:
base_url = "some string"
# skip ssl verification
#
# Optional bool.
# Default value:
skip_ssl = false
}
Usage #
This publisher accepts the following arguments within a publish misp_event_reports block:
# The `publish` block also accepts the generic `format_ref` argument to link to a formatter.
publish misp_event_reports {
# Required string.
# Must be non-empty
#
# For example:
event_id = "some string"
# Required string.
# Must be non-empty
#
# For example:
name = "some string"
# Optional string.
# Must be one of: "0", "1", "2", "3", "4", "5"
# Default value:
distribution = null
# Optional string.
# Default value:
sharing_group_id = null
}