You can add or edit indicators of compromise such as domain names, file hashes, email, and IP addresses for use in search, configuration, or intelligence matching. You can add indicators one at a time or you can upload multiple indicators from a CSV or JSON file. You can only add indicators to lists that you have created.
Important
A maximum of 28,000 indicators can be added to a list for an index search. A maximum of 8,000 indicators can be added to a list for an archive search. A message is displayed if you attempt to add more indicators.
Open the list and click Add Indicator.
Enter an indicator value.
Select its type from the Type menu (Email, FQDN, IPv4, IPv6, MD5, Misc, or SHA-1).
Select a Risk value (Low, Medium, High, or Critical).
Enter any notes in the Notes box.
Click Save.
Note
For more information about formatting your data in a CSV or JSON file, see Creating a CSV or JSON file for custom indicators.
Click Add Indicator.
Click Choose File.
Select a CSV or JSON file and click Open.
Note
Alternately, you can drag a CSV or JSON file into the UI.
If the upload completes successfully, a brief success message appears, and the indicators are added to the list.
If the upload completes with errors, click the View Rejected link in the error message. The Failed Indicators window tells you the reason validation failed on particular indicators. The Index value provided in the error message is the line number that contains the error. Troubleshoot errors and reimport the file, if necessary.
Click Save.