The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IOC STIX XML file upload errors

Prev Next

When you add a manual upload cyber threat feed, Trellix ESM sends the Structured Threat Information eXpression (STIX) file to the Indicator of Compromise (IOC) engine to be processed.

If there is a problem with the upload, you receive one of these errors.

Cyber threat manual upload errors

Error

Description

Troubleshooting

ER328 — Invalid STIX format

The file format is incorrect.

  • Make sure that the uploaded file is a STIX file. The engine supports STIX version 1.1.

  • Read the STIX documentation to verify that the schema is valid.

    • Open Standards for Information Society (OASIS) — Organization in charge of STIX standards.

    • STIX Project — Contains the various STIX data models, schemas, and xsd documents.

ER329 — No supported IOCs found

The uploaded STIX file doesn't contain indicators that are normalized for Trellix ESM.

If a specific indicator needs to be processed, contact Support so that it can be normalized.