I have some troubles with Threatbus using with Kafka. I want to ship IOCs from MISP to kafka via ThreatBus
That am i dooing wrong?
I have installed misp and dockerized kafka, manually created topic with name indicator, and run threatbus with my config-file.
logging:
console: true
console_verbosity: INFO # One of "DEBUG", "INFO", "WARNING", "ERROR", "CRITICAL".
file: false
plugins:
backbones:
inmem: {}
apps:
misp:
api:
host: https://localhost
ssl: false
key: zBkLoUb7Q*******************Vqz
filter:
- orgs:
- "2"
kafka:
topics:
- indicator
poll_interval: 1.0
# # All config entries are passed as-is to librdkafka
# # https://github.com/edenhill/librdkafka/blob/master/CONFIGURATION.md
config:
bootstrap.servers: "kafka:9092"
group.id: "threatbus"
auto.offset.reset: "earliest"
version: '3.5'
networks:
default:
name: threatbus
external: false
volumes:
kafka_data:
zookeeper_data:
services:
zookeeper:
image: docker.io/bitnami/zookeeper:3.7
restart: unless-stopped
ports:
- "2181:2181"
volumes:
- "zookeeper_data:/bitnami"
- "./zookeeper_data/:/bitnami/zookeeper/"
environment:
- ALLOW_ANONYMOUS_LOGIN=yes
- ZOO_SERVER_ID=1
kafka:
image: docker.io/bitnami/kafka:2
restart: unless-stopped
ports:
- "9092:9092"
volumes:
- "kafka_data:/bitnami"
- "./kafka_data/:/bitnami/kafka/data"
environment:
- KAFKA_BROKER_ID=1
- KAFKA_ADVERTISED_PORT=9092
- KAFKA_CFG_LISTENERS=PLAINTEXT://:9092
# - KAFKA_CFG_ADVERTISED_LISTENERS=PLAINTEXT://kafka:9092
- KAFKA_CFG_ADVERTISED_LISTENERS=PLAINTEXT://kafka:9092
- KAFKA_CFG_PLAINTEXT_HOST://localhost:9092
- KAFKA_CFG_ZOOKEEPER_CONNECT=zookeeper:2181
- KAFKA_CFG_AUTO_CREATE_TOPICS_ENABLE=false
- KAFKA_CFG_LOG_RETENTION_BYTES=21474836480
- KAFKA_CFG_LOG_RETENTION_HOURS=24
- ALLOW_PLAINTEXT_LISTENER=yes
- KAFKA_CFG_DELETE_TOPIC_ENABLE=true
depends_on:
- zookeeper