5.6.16. `Config - sigflow/sources`
screen of the legacy web UI
This screen is only accessible to members of the operator group.
Note
For administrator group members, the following message is displayed: `Error 403: Insufficient permissions.`
`Sources`
command from the sub-menu `Config/Sigflow`
, the following screen is displayed.Defining the sources of signatures for the detection engine
Managing the existing sources
Managing the rule set files made available by the sources
Managing the categories and rules of these files
The `Sources`
screen contains the following sections:
Item |
Name |
Position |
---|---|---|
1 |
|
Indicates the list of existing sources |
2 |
|
List of streams |
3 |
|
Area of possible actions. The possible actions listed below depend on the context: |
4 |
|
|
5 |
|
|
6 |
|
Field indicates the number of sources defined |
7 |
Description of a source |
Defined source. This includes the following types of information:
You can add a MIPS source. To do this, refer to the procedure in Configuring the connection to the MISP |
8 |
Search field |
Enables a search |
9 |
|
Displays the |
10 |
context menu |
Displays the management sub-menu for this source for access to the |
Note
You can have two LastinfoSec entries:
An entry named`LastinfoSec(Experimental)`
: this entry only exists if the GCenter was in version V101 and migrated to V102.This entry must be deleted. To do this, refer to Procedure to delete a source. An entry named`LastinfoSec`
: this entry is created in V102.This entry must be kept and used.
After pressing the `View`
button (9), the `Sources: view`
screen contains the following sections:
Item |
Name |
Position |
---|---|---|
1 |
Source field |
Indicates the selected source (here CTI). it includes the following fields: |
10 |
Source creation field |
|
9 |
Update field |
|
2 |
|
Area of possible actions. The possible actions listed below depend on the context. |
8 |
|
|
7 |
|
|
6 |
|
|
5 |
|
|
3 |
|
List of categories. This includes three types of information:
|
4 |
Search field |
Enables searching for text in the categories including the description field of the rules |
Note
See the SIGFLOW engine rule sources procedure to :
Visualization and management of sources
Visualization and management of rule files