misp42splunk icon indicating copy to clipboard operation
misp42splunk copied to clipboard

last field Deprecated

Open rafiki31130 opened this issue 1 year ago • 2 comments

Hi, The 'last' field is deprecated in MISP. The right parameter tu use is timestamp, using the last field, the request take a lot longuer than expected and can generate timeouts on important sources.

Can me manualy managed with this parameter: json_request="{"timestamp":"1d"}" But it would be great if directly managed by the command.

Thanks !

rafiki31130 avatar Apr 03 '23 10:04 rafiki31130

Hi, thank you for email Yes normally with json_request you can query exactly like with REST client

Do you have link to documentation on using timestamp over last? I will align in a future release soon Remi

Le 3 avril 2023 12:11:46 GMT+02:00, rafiki31130 @.***> a écrit :

Hi, The 'last' field is deprecated in MISP. The right parameter tu use is timestamp, using the last field, the request take a lot longuer than expected and can generate timeouts on important sources.

Can me manualy managed with this parameter: json_request="{"timestamp":"1d"}" But it would be great if directly managed by the command.

Thanks !

-- Reply to this email directly or view it on GitHub: https://github.com/remg427/misp42splunk/issues/230 You are receiving this because you are subscribed to this thread.

Message ID: @.***> -- Sent with K-9 Mail.

remg427 avatar Apr 03 '23 11:04 remg427

Hi,

My bad, the documentation indicates well that the last field is deprecated but replaced by publish_timestamp, not timestamp.

However interesting fact: the requests over timestamp (corresponding to latest update time) are well faster than publish_timestamp (or last) surely because timestamp is indexed and the others aren't. Don't know if you want to take into account but it can be usefull.

Source, fields detailed list here: RESTful searches with XML result export

Kind regards, Christian

rafiki31130 avatar Apr 03 '23 12:04 rafiki31130