localsig localfeed enable

Prev Next

Enables and disables a local feed on the Central Management System appliance that retrieves IOC data from local Network Security, EX Series, File Protect, and Malware Analysis appliances and sends the data to the Network Security appliance for immediate blocking. The no form of this command disables the local feed.

By default, the local feed is disabled. When enabled, the local feed displays on the Appliance Settings: 3rd Party Feeds page on the Central Management System appliance. You cannot delete the local feed.

Note

Enable local signature generation settings before enabling the local IOC feed using the localsig enable command. If local signature generation settings are not enabled, the local IOC feed is not enabled.

Enabling the local feed and third-party feeds on the Central Management System appliance can negatively impact the performance of the appliance.

Syntax

[no] localsig localfeed enable

Parameters

No

Disables the local feed on the appliance.

Example

The following example enables the Central Management System appliance local feed. Malicious file hashes detected in alerts from FireEye products are obtained by the Central Management System appliance and sent to the Network Security appliance:hostname (config) # localsig localfeed enable

User role

Admin

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 8.0