The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Edit Threat Feed - Import

Prev Next

This URL imports a STIX file to update an existing threat feed.

Resource URL

POST threatfeedintelligence/{domainId}/importAndSaveThreatFeed

Request Parameters

URL Parameters:

Field Name

Description

Data Type

Mandatory

domainId

Domain Id

Number

Yes

Payload Parameters:

Field Name

Description

Data Type

Mandatory

feedId

Existing Feed Id to update

Number

Yes

feedName

Name of the threat feed

String

Yes

publisherName

Name of the threat feed publisher

String

Yes

visibleToChildDomain

Visibility to child domains

Boolean

Yes

feedSourceType

Threat feed source type (auto filled, Value = 1)

Number

Yes

feedFormat

Threat feed format (auto filled, Value = 1)

Number

Yes

iocTypesEnabled

List of enabled IoC types: IOC_IPv4_ENDPOINT_TYPE = 1, IOC_IPv6_ENDPOINT_TYPE = 2, IOC_IPv4_CIDR_TYPE = 3, IOC_IPv6_CIDR_TYPE = 4, IOC_HOST_DOMAIN_NAME_TYPE = 5, IOC_URL_TYPE = 6, IOC_FILE_HASH_TYPE = 7

Array

Yes

Important

The request also includes the STIX file as a multipart attachment.

Response Parameters

The following fields are returned if the request parameters are correct, otherwise error details are returned.

Field Name

Description

Data Type

success

Success status (true or false)

Boolean

msg

Message

String

errMsg

Error message

String

data

Data

String

errorCode

Error code

Number

Details of data:

Field Name

Description

Data Type

feedId

Unique identifier for the threat feed

Number

feedName

Name of the threat feed

String

publisherName

Name of the publisher

String

feedSourceType

Type of feed source

Number

ownerDomainId

ID of the owner domain of the threat feed

Number

lastUpdated

Last updated time - Unix epoch (in milliseconds)

Number

iocTypesEnabled

List of enabled IoC types

Array (Number)

visibleToChildDomain

Visibility to child domains

Boolean

ownerDomain

Name of the owner domain in which the threat feed exists

String

assignedToSensors

List of assigned Sensors

Array

fromMoM

Indicates if it is from the Central Manager

Boolean

Example

Request

POST https://<Manager_IP>/sdkapi/threatfeedintelligence/101/importAndSaveThreatFeed

Payload

{
    "feedId": 9,
    "feedName": "Testfeed8",
    "domainId": 101,
    "publisherName": "test1",
    "feedSourceType": 1,
    "feedFormat": 1,
    "iocTypesEnabled": [
        1,
        2,
        3,
        4,
        5,
        6,
        7
    ],
    "visibleToChildDomain": true
}

Response

{
    "success": true,
    "msg": null,
    "errMsg": null,
    "data": {
        "feedId": 9,
        "feedName": "Testfeed8",
        "publisherName": "test1",
        "feedSourceType": 1,
        "ownerDomainId": 0,
        "lastUpdated": 1761214773000,
        "iocTypesEnabled": [
            1,
            2,
            3,
            4,
            5,
            6,
            7
        ],
        "visibleToChildDomain": true,
        "ownerDomain": "/My Company",
        "assignedToSensors": [
            "vm600_172_200"
        ],
        "fromMoM": false
    },
    "errorCode": 0
}

Error Information

The following error code is returned by this URL:

S.No

Generic Error Codes

ErrorMessage

Error Reason

1

1001

Bad URL - HTTP 404 Not Found

Mistyped URL

Internal Error – Null

Incorrect Input data, authentication issues