Skip to content
This repository has been archived by the owner on Sep 20, 2023. It is now read-only.

How to enable/update Analyzers in training VM ? #63

Open
vletoux opened this issue Apr 2, 2020 · 1 comment
Open

How to enable/update Analyzers in training VM ? #63

vletoux opened this issue Apr 2, 2020 · 1 comment

Comments

@vletoux
Copy link

vletoux commented Apr 2, 2020

Seems stupid but in https://github.com/TheHive-Project/TheHiveDocs/blob/master/training-material.md, it is indicated that "With the new version, analyzers are disabled by default. The training VM is delivered with Abuse Finder, File_Info, Msg_Parser and MaxMind GeoIP enabled."

Ok, so I have to update them (https://github.com/TheHive-Project/CortexDocs/blob/master/installation/install-guide.md#updating)

But I have to go to a specific directory and update the git code:
/opt/Cortex-Analyzers

But this directory doesn't exist in the VM
image

Ok, maybe the git directory is located elsewhere, let's locate it:
image

Maybe there is an alternative directory configured in cortex:
image

In short I've used the training VM to play with the application, and I see only a few analyzers.

I suggest to modify the VM or to update the documentation to have the same path in the VM that in the doc.

@vletoux
Copy link
Author

vletoux commented Apr 2, 2020

seems that the file /etc/cortex/application.conf needs to be edited to comment the urls and uncomment the path
image

Then issue a git clone and then follow the instruction to update the python requirements

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant