connectors
connectors copied to clipboard
[Sentinel] Observing 2 different IDs for each indicator coming from OpenCTI
Description
For each indicator pushed from OpenCTI to Sentinel, we see 2 different ID's
Environment
- OpenCTI version: 6.5.0
Reproducible Steps
Steps to create the smallest reproducible scenario:
- Create a Live Stream to push indicators from OpenCTI to Sentinel
Expected Output
One ID for each indicator pushed from OpenCTI to Sentinel
Actual Output
Two IDs for each indicator pushed from OpenCTI to Sentinel
Additional information
In Notion investigation page and you can reach out to me to see details.
@EinatAR: comment in the notion page.
Checked with @EinatAR, close for now and can be re-opened if needed