Uploading a third-party feed using the Web UI

Prev Next

Follow these steps to upload up to 30 unique third-party feeds to the File Protect appliance from a flat file or an XML-based file in STIX 1.2 format.

Note

You can upload a third-party feed only using the Web UI only.

A unique name is required for each feed. The feed name that you specify appears as the malware name in the Alerts > Alerts > Alerts page of the appliance Web UI. For details about how to view the details of a custom feed, see Viewing custom feed details using the Web UI.

Use the Create Feed dialog box to upload a third-party feed to the appliance.

NX_IOCFeeds_CreateFeed_scap.png

Important

If you add a file hash feed to the appliance but you do not want to impact appliance performance, you can disable the option to inspect and calculate MD5 or SHA-256 hash files. See Enabling or disabling hash file inspection using the CLI.

Prerequisites
  • A standalone File Protect appliance deployed in TAP mode or inline mode.

  • Admin access to the appliance Web UI.

  • A connection from the appliance to the Dynamic Threat Intelligence (DTI) Cloud.

  • A flat file or an XML-based file in STIX 1.2 format that contains custom blacklist entries. The file must be accessible from the local desktop from which you access the appliance Web UI. For details, see Creating a custom blacklist from third-party feeds.

To upload a third-party feed to a standalone File Protect appliance:
  1. Log in to the appliance as an administrator.

  2. Choose Settings > 3rd Party Feeds. The page lists the custom feeds that are uploaded.

  3. Select the Enable File IOC checkbox to apply all the feeds uploaded from 3rd party and Security Content. A confirmation message informs you about the performance impact when new feeds are created in the File Protect appliance. Click Yes to enable file IOC. Click No to add file hashes to the appliance without impacting the appliance performance.

  4. Click Upload New Feed.

  5. Enter the name of the feed in the Feed Name field.

  6. To override an existing feed with an updated flat file, select the Override checkbox.

  7. Click Choose File. The Create Feed dialog box appears.

  8. Choose content type from the Type drop-down menu.

    • IP

    • Domain

    • URL (or RegEx URL if applicable)

    • Hash MD5

    • Hash SHA‑256

    • STIX

  9. Choose the feed action from the Action drop-down menu.

    • Alert

    • Block

    • Allow (for Domain content only)

  10. (Optional) Enter explanatory information about the feed in the Comment field.

  11. Click Upload to upload the feed.

    • The system checks the entries in the custom blacklist file. A progress message appears:

      NX_IOCFeed_CreationSucceeded_scap.png
    • If there is a problem with the feed that you imported (for example, invalid entries or the wrong format), the following message appears:

      NX_IOCFeed_ValidationFailed_scap.png