IBM Security QRadar SOAR

 View Only
  • 1.  MISP error while creating incident

    Posted 30 days ago
    Hello,
    I'm coming across this error while creating an incident. That's the same while creating a simulation too. After i click "close", the error pop up closes, and I'm back at the create incident page. 
    How can i resolve this?


    ------------------------------
    Janeesh George
    ------------------------------


  • 2.  RE: MISP error while creating incident

    Posted 30 days ago

    Hi Janeesh 

    What version of the MISP app do you have installed? 

    The latest app on the App Exchange is 3.0.2 which uses playbooks (not workflows).  I notice in the error message that the error is in the pre-processor script of a workflow.

    The 3.0.2 app only has manual playbooks.  It sounds like some automatic rule is getting triggered when you are creating an incident. Do you have the MISP custom threat service installed?

    AnnMarie



    ------------------------------
    AnnMarie Norcross
    ------------------------------



  • 3.  RE: MISP error while creating incident

    Posted 30 days ago

    Hi AnnMarie,

    Misp is no longer in our environment. We had it removed, it was an older version.

    Also, I've disabled the "Create attribute" rule and get the same error.

    And i see "rc-cts-misp-1.1.1.tar.gz" is installed. 



    ------------------------------
    Janeesh George
    ------------------------------



  • 4.  RE: MISP error while creating incident

    Posted 29 days ago

    Sounds like you should unistall all of the MISP components from SOAR.

    To uninstall the threat service you can run this command on the appliance

    sudo resutil threatserverdel -name MISP



    ------------------------------
    AnnMarie Norcross
    ------------------------------