This URL imports a STIX file to update an existing threat feed.
Resource URL
POST threatfeedintelligence/{domainId}/importAndSaveThreatFeed
Request Parameters
URL Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain Id | Number | Yes |
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Existing Feed Id to update | Number | Yes |
| Name of the threat feed | String | Yes |
| Name of the threat feed publisher | String | Yes |
| Visibility to child domains | Boolean | Yes |
| Threat feed source type (auto filled, Value = 1) | Number | Yes |
| Threat feed format (auto filled, Value = 1) | Number | Yes |
| List of enabled IoC types: IOC_IPv4_ENDPOINT_TYPE = 1, IOC_IPv6_ENDPOINT_TYPE = 2, IOC_IPv4_CIDR_TYPE = 3, IOC_IPv6_CIDR_TYPE = 4, IOC_HOST_DOMAIN_NAME_TYPE = 5, IOC_URL_TYPE = 6, IOC_FILE_HASH_TYPE = 7 | Array | Yes |
Important
The request also includes the STIX file as a multipart attachment.
Response Parameters
The following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Success status (true or false) | Boolean |
| Message | String |
| Error message | String |
| Data | String |
| Error code | Number |
Details of data:
Field Name | Description | Data Type |
|---|---|---|
| Unique identifier for the threat feed | Number |
| Name of the threat feed | String |
| Name of the publisher | String |
| Type of feed source | Number |
| ID of the owner domain of the threat feed | Number |
| Last updated time - Unix epoch (in milliseconds) | Number |
| List of enabled IoC types | Array (Number) |
| Visibility to child domains | Boolean |
| Name of the owner domain in which the threat feed exists | String |
| List of assigned Sensors | Array |
| Indicates if it is from the Central Manager | Boolean |
Example
Request
POST https://<Manager_IP>/sdkapi/threatfeedintelligence/101/importAndSaveThreatFeed
Payload
{
"feedId": 9,
"feedName": "Testfeed8",
"domainId": 101,
"publisherName": "test1",
"feedSourceType": 1,
"feedFormat": 1,
"iocTypesEnabled": [
1,
2,
3,
4,
5,
6,
7
],
"visibleToChildDomain": true
}Response
{
"success": true,
"msg": null,
"errMsg": null,
"data": {
"feedId": 9,
"feedName": "Testfeed8",
"publisherName": "test1",
"feedSourceType": 1,
"ownerDomainId": 0,
"lastUpdated": 1761214773000,
"iocTypesEnabled": [
1,
2,
3,
4,
5,
6,
7
],
"visibleToChildDomain": true,
"ownerDomain": "/My Company",
"assignedToSensors": [
"vm600_172_200"
],
"fromMoM": false
},
"errorCode": 0
}Error Information
The following error code is returned by this URL:
S.No | Generic Error Codes | ErrorMessage | Error Reason |
|---|---|---|---|
1 | 1001 | Bad URL - HTTP 404 Not Found | Mistyped URL |
Internal Error – Null | Incorrect Input data, authentication issues |