Deleting third-party IOC feeds using the Web UI

Prev Next

Follow these steps to delete third-party feeds from the Central Management System appliance using the Web UI.

Note

You can delete a third-party feed only using the Web UI.

The local feed is managed (uploaded and deleted) automatically by the Central Management System appliance. Local feed data is automatically removed when the corresponding locally generated rules (localsig rules) expire. You cannot delete local feed data.

Important

When a file hash feed is added on the Central Management System appliance and you do not want to impact appliance performance, choose one of the following options to stop calculating the MD5 or SHA-256 hashes that are detected in network traffic:

  • Log in locally to each managed Network Security appliance to disable the file inspection feature. Use the no bottracker fi-md5 enable command to disable calculating MD5 hashes. Use the no bottracker fi-sha256 enable command to disable calculating SHA-256 hashes.

  • Delete all the hash MD5 or SHA-256 feed files on the Central Management System appliance Web UI. However, all the hash MD5 or SHA-256 feed files will be deleted from all the managed Network Security appliances that are connected to this Central Management System appliance.

For details about how to enable or disable the option to inspect and calculate MD5 or SHA-256 hash files, refer to the Network Security User Guide.

Prerequisites
  • Log in to the Web UI of the Central Management System appliance as Admin.

  • Upload one or more feeds to a managed Network Security appliance from a flat file or an XML-based file in STIX 1.2 format. For details about how to upload a feed, see Uploading a custom feed.

To delete a third-party IOC feed:
  1. In the Web UI, choose Settings > Appliance Settings.

  2. Select the managed Network Security appliance and then select 3rd Party Feeds.

    The page lists the custom feeds that are uploaded.

  3. In the table, select the check box next to the third-party feed you want to delete. You can select multiple feeds at one time.

    CM_CustomIOCDeleteFeed_scap.png
  4. Click Delete Feed. A dialog box prompts you to confirm your changes.

  5. Click Yes.

    The feed is removed from the table. The following message appears:

    CM_CustomIOCDeleteFeedConfirm_scap.png
  6. Close the message.