To enable or disable a feed, send the following request:
POST https://<IA_IP_address>:<port_number>/threatintelservice/v1/feedname/<feed_name>/<active>
Note
To use this request, your user account must have admin privileges.
Required headers:
X-Username: <user> X-Role: <role>
Options
IA_IP_address—The IP address of the NDR appliance running the NDR API.
port_number—The port number of the NDR appliance running the NDR API.
token—This token authenticates the session. By default, the session times out after 24 hours.
user—The user ID.
role—The user's role.
Parameters
feed_name—(string) The name of the feed.
active—(Boolean) True enables the feed, false disables the feed.
Example
POST https://xxx.xxx.xxx.xxx:443/threatintelservice/v1/feedname/mynewfeed/true
Required headers:
Cookie: px=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx > X-Username: wheel X-Role: wheel
Enable a feed: Response
HTTP/1.1 [Response Code] [Response Message]
{
"payload": "Feed's active/inactive changed.",
"status": "OK"
}Response fields
Response Code—A standard HTTP response code.
200—Request successful; the feed names was created.
Response Message—A standard HTTP response message.
OK—Request successful; the feed names were returned.
Date—Standard HTML date format.
Content Type—The response format.
payload—Confirms that the feed's status changed.
status—Status of the feed.
Example
HTTP/1.1 200 OK
{
"payload": "message",
"status": "status"
}cURL code sample: Enable a feed
curl -k -X POST --cookie "px=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx" -H "X-Username: wheel" -H "X-Role: wheel" https://xxx.xxx.xxx.xxx:443/threatintelservice/v1/feedname/mynewfeed/true
This cURL sample includes the following options:
-k—This option explicitly allows cURL to perform insecure SSL connections and transfers, which allows you to test your SSL connection without installing a CA certificate.-X POST—Specifies using the POST method.--cookie "px=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"—This option specifies the authentication token for this session.-H "X-Username: wheel"—User name.-H "X-Role: wheel"—User role.https://xxx.xxx.xxx.xxx:443/threatintelservice/v1/feedname/mynewfeed/true—The feed name request URL. Replacexxx.xxx.xxx.xxxwith the IP address of your NDR appliance,mynewfeedwith the name you want to create, and true with the enabled status you want.
Results
This example enables the specified feed.