Downloads custom IOC files from the Central Management System to a file for Network Security appliances only.
GET https://<address>/wsapis/[v1.2.0|v2.0.0]/customioc/feed/download/<Feed-Name>
Availability
This command is available on the following appliances:
Central Management System
Required headers:
X-FeApi-Token: [API-Token] X-FeClient-Token: [Client-Token] Content-Type: application/octet-stream
Body:
[Output-File]
Options
address—The IP address of the appliance running the Web Services API.
Feed-Name—Name of an existing feed.
API-Token—This token authenticates the session. By default, the session times out after 15 minutes of inactivity.
Client-Token—(Optional) This client token is provided by Trellix. For more information about the client token, contact your sales representative.
Output-File—The file that will contain the feed and, optionally, the file path.
Example request
GET https://xxx.xxx.xxx.xxx:443/wsapis/v2.0.0/customioc/feed/testFeed
Request headers:
X-FeApi-Token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx X-FeClient-Token: BigDataInc
Request Body:
feed.txt
Download a custom IOC file response
After the request is received, the Central Management System appliance validates the API token and saves the feed in the specified file.
HTTP/1.1 [Response Code] [Response Message] Date: [Date]
Body:
[Output-File]
Response fields
Response Code—A standard HTML response code.
200—Request successful.
500—Request unsuccessful because the server has encountered a problem; retry later.
Response Message—A standard HTML response message.
OK—Request successful.
Error trying to process submission—Request unsuccessful because the server has encountered a problem; retry later.
Date—Standard HTML date format.
Output-File—The file that will contain the feed.
Example
HTTP/1.1 200 OK Date: Fri, 17 Nov 2017 08:00:00 GMT
Body:
feed.txt
cURL code sample: download a custom IOC file
The following code sample can be copied and executed from any command-line interface that includes the cURL library. This sample builds on the authentication cURL code sample.
Note
In this sample, line breaks are added for readability. Remove these line breaks before you paste the code sample into your command-line tool.
curl -qgsSk --no-progress-bar --header "X-FeApi-Token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" --header "Content-Type:application/octet-stream" "https://xxx.xxx.xxx.xxx:443/wsapis/v2.0.0/customioc/feed/download/testFeed" -o /cygdrive/c/cygwin/feed.txt
This cURL sample includes the following options:
-q—This option specifies that thecurlrcconfig file is not read or used. Although this is an optional setting, Trellix recommends that you include this option.-g—This option turns off the URL globbing parser. Although this is an optional setting, Trellix recommends that you include this option.-s—This option turns off the progress meter and error message. Although this is an optional setting, Trellix recommends that you include this option.-S—When used with the-soption, this option shows error messages if your cURL switch fails. Although this is an optional setting, Trellix recommends that you include this option.-k—This option explicitly allows cURL to perform insecure SSL connections and transfers. This allows you to test your SSL connection without installing a CA certificate.--no-progress-bar—This option suppresses the cURL download progress bar, which can interfere with the request.--header "X-FeApi-Token: xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"—This custom header includes the API-Token that was returned by your appliance during the authentication request. In the authentication cURL code sample, this token was included in theauth.txtfile. Replace the token in the sample with the token received in the response to your authentication request.-H "Content-Type: application/octet-stream"—This header specifies that the request is in a binary file."https://xxx.xxx.xxx.xxx:443/wsapis/v2.0.0/customioc/feed/download/testFeed"—The custom IOCs request URL. Replace the IP addressxxx.xxx.xxx.xxxwith the IP address of your appliance. ReplacetestFeedwith the name of the feed of interest.-o /cygdrive/c/cygwin/feed.txt—The file that will contain the feed and the file path.
Results
This example downloads the feed into the specified file.