# Shodan Integration

**URL:** <https://discuss.elastic.co/t/shodan-integration/223425>\
**Category:** SIEM\
**Created:** [March 12, 2020, 11:33pm UTC](https://discuss.elastic.co/t/shodan-integration/223425 "2020-03-12T23:33:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [March 12, 2020, 11:33pm UTC](https://discuss.elastic.co/t/shodan-integration/223425/1 "2020-03-12T23:33:54Z")

</div>

Has anyone managed to get [Shodan.io](http://Shodan.io) alerts into Elastic SIEM? I'm trying to use kubi-ecs-logger logging library and the shodan python api to send ECS alerts and wondered if anyone is interested in collaborating?

H

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [March 17, 2020, 2:30am UTC](https://discuss.elastic.co/t/shodan-integration/223425/2 "2020-03-17T02:30:56Z")

</div>

Ok I've figured out a crude implementation, in summary :

- Setup shodan to monitor for new\_services / unknown
- run the shodan cli `shodan stream --alert=all --compresslevel 0 --datadir=/local`
- run a filebeat prospector with the following config

```auto
filebeat.inputs:
- type: log
  paths:
    - "/local/*"
  json.add_error_key: true
  fields_under_root: true
  fields:
    event:
      type: "change"
      kind: "alert"
      module: "shodan"
      category: "network"

```

TODO

- fields are not yet mapped to the Elastic Common Schema - a python script needs to be written to poll the API and map shodan fields to ECS

Here is the result :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/a/3aca5a3bf0d0a4b0f80e23f889a82e6f3801c37f.png)

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [March 17, 2020, 11:46pm UTC](https://discuss.elastic.co/t/shodan-integration/223425/3 "2020-03-17T23:46:33Z")

</div>

Hi hilt86,

Woa, that is really cool! You should put what you have on a github project and make it into a python package for people to collaborate on?

With just what you have above, you should be able to create signals from it at this point. But enriching the data by transforming what makes sense into ECS will make it even more useful.

---

<div class="post-metadata">

**Author:** ![hilt86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hilt86/32/20308_2.png) [@hilt86](https://discuss.elastic.co/u/hilt86)\
**Post date:** [March 26, 2020, 7:15am UTC](https://discuss.elastic.co/t/shodan-integration/223425/4 "2020-03-26T07:15:38Z")

</div>

Yeah that would be cool - is there a python lib for ECS that would make this easier?

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [April 1, 2020, 12:41pm UTC](https://discuss.elastic.co/t/shodan-integration/223425/5 "2020-04-01T12:41:18Z")

</div>

There might be some things that are helpful in some of the folders within ECS:

> **[elastic/ecs](https://github.com/elastic/ecs)**
>
> Elastic Common Schema. Contribute to elastic/ecs development by creating an account on GitHub.

such as this:

> **[elastic/ecs](https://github.com/elastic/ecs/tree/master/generated)**
>
> Elastic Common Schema. Contribute to elastic/ecs development by creating an account on GitHub.

and a schema reader:

> <https://github.com/elastic/ecs/blob/master/scripts/schema_reader.py>

But I haven't added any contributions or used the python generators before. It's interesting though as the definitions of ECS are in yml files and there's hooks to generate things from the schema such as ECS mappings, etc...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 12:41pm UTC](https://discuss.elastic.co/t/shodan-integration/223425/6 "2020-04-29T12:41:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
