Enables or disables a specific managed Network Security appliance to receive indicator (IOC) customizations from a third-party feed. You can verify that this feature is enabled or disabled when you log in to a managed Network Security appliance.
Important
Before you can receive third-party IOC feeds, you need to create a custom blacklist for the IOCs in the Web UI. For more information on creating a custom blacklist, see "Creating a Custom Blacklist from a Third-Party Feed," in the Central Management System Administration Guide.
Note
IOC customizations are not supported on managed Trellix Network Security 300 appliances.
Note
This feature is enabled by default when you add the Network Security appliance to the Central Management System appliance. The DTI feeds are automatically pushed to the managed Network Security appliance.
Syntax
[no] custom content enable on lms <appliance>
Parameters
noUse the no form of this command to disable third-party IOCs on a specific managed Network Security appliance.
<appliance>A Network Security appliance record name.
Example
The following example enables third-party IOCs on a specific managed Network Security appliance:
hostname (config) # custom content enable on lms nx1
The following example disables third-party IOCs on a specific managed Network Security appliance:
hostname (config) # no custom content enable on lms nx1
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9