Viewing custom feed details

Prev Next

View details about the status of custom IOC feeds, the total number of custom IOC feeds, and the total number of all the custom blacklist entries that you configured on managed Network Security appliances from the Central Management System appliance.

View the local feed status using the CLI.

Track the number of blacklist entries that were configured for each third-party feed using the CLI.

Prerequisites
  • Admin access to the Central Management System appliance.

  • A connection to the Dynamic Threat Intelligence (DTI) Cloud.

  • A managed Network Security appliance is deployed in TAP mode or inline mode.

  • Enable IOCs from custom feeds. For details, see Enabling or disabling dustom IOC feeds .

  • Create a flat file or an XML-based file in STIX 1.2 format that contains custom blacklist entries. Verify that the file is accessible from the local desktop from which you access the Web UI. For details, see Creating a custom blacklist from third-party feeds .

  • Upload one or more third-party feeds to a managed Network Security appliance from a flat file or an XML-based file in STIX 1.2 format. For details about how to upload a feed, see Uploading a third-party feed .