Production-tuned fork of NUKIB/misp for instances with 30k+ tags (OPcache + hide_tag filter)
2.5K
Production-tuned fork of NUKIB/misp for instances with large tag catalogues (30 000+ tags from OpenCTI / Feedly / Recorded Future / misp-galaxy ingestion).
Tracks upstream feature-for-feature — same AlmaLinux 9 base, same PHP 8.3, same Snuffleupagus hardening, same MISP 2.5. Differences are listed below.
nukib/misp| Area | Upstream default | This image |
|---|---|---|
| OPcache memory | 128 MB | 512 MB |
| OPcache interned strings | 8 MB | 32 MB |
| OPcache max files | 10 000 | 20 000 |
FeedsController::edit/add tag picker | Renders every tag in the DB | Renders only WHERE hide_tag = 0 |
The Feeds form fix matters once your tags table is more than a few thousand rows — Chosen.js (the jQuery dropdown library MISP uses) iterates every <option> on init and blocks the browser main thread. Tagging bulk-ingested namespaces with hide_tag = 1 lets them stay in events/correlation but disappear from the Feed default-tag picker.
Drop-in replacement for ghcr.io/nukib/misp:latest. Override MISP_IMAGE in the compose env:
curl -O https://raw.githubusercontent.com/NUKIB/misp/main/docker-compose.yml
MISP_IMAGE=niavasha/misp:latest docker compose up -d
Or set it in a .env file alongside the compose file:
MISP_IMAGE=niavasha/misp:latest
Everything else — env vars, volumes, health checks, first-run admin credentials — matches upstream. See the NUKIB/misp README for full configuration options.
After ingesting feeds that explode the tag count:
UPDATE tags SET hide_tag = 1
WHERE name LIKE 'opencti_label:%'
OR name REGEXP '^(feedly|recorded-future|Intel 471):';
Tags are still searchable, taggable via API, and applied to events — they're just filtered out of the Feed form picker. Reverse with hide_tag = 0.
latest — tracks MISP 2.5Dockerfile and patch live at github.com/niavasha/misp.
Content type
Image
Digest
sha256:de0601da3…
Size
577.6 MB
Last updated
5 months ago
docker pull niavasha/misp