Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

TAXII Feed from Microsoft tutorial error #8988

Closed
jeffrywu28 opened this issue Sep 12, 2023 · 7 comments
Closed

TAXII Feed from Microsoft tutorial error #8988

jeffrywu28 opened this issue Sep 12, 2023 · 7 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@jeffrywu28
Copy link

Describe the bug
Why always error when get the TAXII feed from ms learn
To Reproduce
Steps to reproduce the behavior:

  1. Go to TAXII Connector
  2. Fill this

Friendly name (for server): PickupSTIX-AbuseIPDB-blacklist
API root URL:
https://test.pickupstix.io/taxii2/api2/
Collection ID: system.AbuseIPDB_blacklist
Username: guest
Password: guest
Import indicators: "All available"
Polling frequency: Once an hour

  1. See error

Expected behavior
Not Error.

Screenshots
image

@github-actions
Copy link
Contributor

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

@v-amolpatil v-amolpatil added the Connector Connector specialty review needed label Sep 12, 2023
@v-rbajaj
Copy link
Contributor

Hi @jeffrywu28, thanks for flagging this issue, we will get back to you soon.

@jeffrywu28
Copy link
Author

@v-rbajaj any updates?

@v-rbajaj
Copy link
Contributor

Hi @jeffrywu28, we have reached out to concerned team, waiting for update from them.

@v-rbajaj
Copy link
Contributor

Hi @jeffrywu28,
You would need to find a working TAXII server, and they may need to add MS Sentinel TAXII client IP Address to the allowlist of the server. Please follow this guide: https://learn.microsoft.com/en-us/azure/sentinel/connect-threat-intelligence-taxii

@v-rbajaj
Copy link
Contributor

Gentle Reminder: We are awaiting for your response on this issue. If you still need to keep this issue active please respond on it in the next 2 days . If we don't receive response by given date we will be close this issue.

@v-rbajaj
Copy link
Contributor

Hi @jeffrywu28, Since we have not received a response in the last 5 days, we are closing your issue
#8988 as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

4 participants