# Threat hunting/cifv4 and logstash http filter

**URL:** <https://discuss.elastic.co/t/threat-hunting-cifv4-and-logstash-http-filter/183429>\
**Category:** Logstash\
**Created:** [May 29, 2019, 11:08pm UTC](https://discuss.elastic.co/t/threat-hunting-cifv4-and-logstash-http-filter/183429 "2019-05-29T23:08:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![stcdarrell](https://avatars.discourse-cdn.com/v4/letter/s/a183cd/32.png) [@stcdarrell](https://discuss.elastic.co/u/stcdarrell)\
**Post date:** [May 29, 2019, 11:08pm UTC](https://discuss.elastic.co/t/threat-hunting-cifv4-and-logstash-http-filter/183429/1 "2019-05-29T23:08:03Z")

</div>

hi, i have no idea if this is a good plan or not.. but i'm giving it a good try.  
There is a nice open source threat intelligence platform called cifv4 ([https://csirtgadgets.com/collective-intelligence-framework/](https://csirtgadgets.com/collective-intelligence-framework/)) , it has a rest api to query for various things. I'd like to run ip addresses from my IDS through it to determine if any of the outside/external communications are known bad addresses.

i can reach and perform queries via curl, here is an example:  
curl -X GET "[http://gamma.stc.local:5000/indicators/?q=8.8.8.8](http://gamma.stc.local:5000/indicators/?q=8.8.8.8)" -H "accept: application/json" -H "Authorization: 51d48b312a1fbf6237c885c95244e1a921fda49ee751bbc3614c43c6021dXXXXXXX"

and it works.. it returns a nice JSON full of info..

from what i understand i should be able to set up a logstash .conf to query using the http filter..

--1012-enrich-cifv4.conf--  
filter {  
if [source][address] {  
http {  
url =\> "[http://gamma.stc.local:5000/indicators/](http://gamma.stc.local:5000/indicators/)"  
query =\> { "q" =\> "%{[source][address]}" }  
verb =\> POST  
headers =\> { "Authorization" =\> "51d48b312a1fbf6237c885c95244e1a921fda49ee751bbc3614c43c6XXXXXXXX" }  
target\_body =\> "[source][body]"  
target\_headers =\> "[source][header]"  
} #end http  
} #end if  
} #end filter

this doesnt seem to work.. it doesnt send the IP address in %[source][address]  
i'm pretty new to all of this.. any suggestions would be greatly appreciated

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2019, 11:08pm UTC](https://discuss.elastic.co/t/threat-hunting-cifv4-and-logstash-http-filter/183429/2 "2019-06-26T23:08:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
