Converting my own feeds to bro intel


I do have certain OSINT Feeds and wanted to convert those to intel.dat and later consumed by ELK stack. Can someone guide how do I convert those IP addresses into intel.dat.

This should fit the bill:

If you’re using effective domain you’ll need to to some grep/seding to change it.


Thanks appreciate your quick answer. Let me dive in :slight_smile: