The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

IOC STIX XML file upload errors

Prev Next

When you add a manual upload cyber threat feed, Trellix ESM sends the Structured Threat Information eXpression (STIX) file to the Indicator of Compromise (IOC) engine to be processed.

If there is a problem with the upload, you receive one of these errors.

Cyber threat manual upload errors

Error

Description

Troubleshooting

ER328 — Invalid STIX format

The file format is incorrect.

  • Make sure that the uploaded file is a STIX file. The engine supports STIX version 1.1.

  • Read the STIX documentation to verify that the schema is valid.

    • Open Standards for Information Society (OASIS) — Organization in charge of STIX standards.

    • STIX Project — Contains the various STIX data models, schemas, and xsd documents.

ER329 — No supported IOCs found

The uploaded STIX file doesn't contain indicators that are normalized for Trellix ESM.

If a specific indicator needs to be processed, contact Support so that it can be normalized.