I want to use the rule "Threat Intel Filebeat Module (v7.x) Indicator Match", but it fails due to format of IPs in the records. The problem is the format in the fileset "abuseurl" in threatintel.indicator.ip, for example you can find "42.232.243.051" in there, which is an invalid IP.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.