Enables or disables a Central Management System appliance to receive indicator (IOC) customizations from a third-party feed and distribute them to all managed Network Security appliances. When the third-party IOC feed feature is disabled, DTI feeds are not pushed to all managed Network Security appliances.
Important
Before you can receive third-party IOC feeds, you need to create a custom blacklist for the IOCs in the Web UI. For more information on creating a custom blacklist, see "Creating a Custom Blacklist from a Third-Party Feed," in the Central Management System Administration Guide.
Note
IOC customizations are not supported on managed FireEye NX 300 models.
Note
This feature is enabled by default when you add the Network Security appliance to the Central Management System appliance. The DTI feeds are automatically pushed to the managed Network Security appliance.
Syntax
[no] custom content enable
Parameters
noUse the no form of this command to disable third-party IOCs.
Example
The following example enables third-party IOCs on all managed Network Security appliances:
hostname (config) # custom content enable
The following example disables third-party IOCs on all managed Network Security appliances:
hostname (config) # no custom content enable
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9