This topic shows you how to use the Endpoint Security (HX) Web UI to create a custom indicator rule by uploading lists of conditions.
Important
Linux currently only allows the creation of network connections using custom indicator rules.
Select Rules from the Configure section of the main menu to access the Rules page.
On the Indicators tab, click the + Create indicator button.
On the Create Indicator page, specify an indicator rule name in the Indicator Name box. Indicator rule names can use the following characters:
Capital and lowercase letters
A(a) throughZ(z)Positive numbers
0through9Spaces
Special characters:
()-.,_[]
Select the operating systems (Windows or Mac OS X) associated with the indicator rule in the Operating System list.
Important
Do not automatically accept the default operating system. Be sure to select an operating system before you add any conditions for the indicator.
On the Create Indicator page, under 1. Define indicator, go to upload a list of conditions. Click the Browse button next to the Browse for intel file box, and locate and select a file to upload.
Click Upload. A message under the Browse for intel file box shows the number of conditions uploaded and the number of lines in the file.
Important
If your list contains more than 10,000 conditions or any of the conditions is formatted incorrectly, an error message appears. Endpoint Security (HX) displays a link to an error list that shows the line number of each condition that had one or more problems, the value that was in error, and an explanation of the error.
For example: <IP-address> - indicator formatted incorrectly
The error list also shows any blank lines and duplicate listings in the file. The number of conditions uploaded and lines in the original file may differ if there are problems or duplicates.
Custom indicator condition values can be set to a maximum of 255 ASCII and escaped Unicode characters. The Endpoint Security (HX) truncates uploaded indicator conditions that are longer than 255 characters. False positives can result if a condition is truncated.
In the pane on the right side of the Create Indicator page, you can preview the conditions you uploaded.
To upload additional lists of conditions:, repeat the previous 2 steps. Make sure that the Append to indicator option is selected. To add individual conditions, follow the instructions in Adding individual conditions to a custom indicator rule in the Web UI.
Repeat until you have added all the new conditions that you want to include in the indicator.
In the preview pane, hover over unnecessary conditions and click the x icon in the upper right corner to delete them.
(Optional) Under 2. Describe indicator, you can enter a description of the indicator.
This description appears on the Indicator Details tab of the Indicators page Details pane.
Click the Create button on the right.
Your custom indicator rule appears on the Rules page.