Threat Intelligence Rule fails

I want to use the rule "Threat Intel Filebeat Module (v7.x) Indicator Match", but it fails due to format of IPs in the records. The problem is the format in the fileset "abuseurl" in threatintel.indicator.ip, for example you can find "42.232.243.051" in there, which is an invalid IP.

How can I get around this error?

Best regards,
Norbert

can you share your index mapping for the index? This should have prevented it from being added in the first place

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.