I was trying to setup a usecase to do the following:
1.) Download a txt file containing known malicious IP's.
2.) Compare existing netflow traffic logs to see if there is a match against any of the malicious IP's
3.) Send an alert if a connection is found with these malicious IP's.
That link is for creating a use case that involves this step, this thread is only for that one step of injecting a list into elastic. This step can be applied in many use cases.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.