This URL saves IoC exclusion values for a threat feed.
Resource URL
POST threatfeedintelligence/saveIoCValues
Request Parameters
Payload Parameters:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| Domain Id | Number | Yes |
| Threat feed Id | Number | Yes |
| List of IoC values to exclude/include | Array | Yes |
Details of excludedValues:
Field Name | Description | Data Type | Mandatory |
|---|---|---|---|
| IoC value | String | Yes |
| The IoC type: IOC_IPv4_ENDPOINT_TYPE = 1, IOC_IPv6_ENDPOINT_TYPE = 2, IOC_IPv4_CIDR_TYPE = 3, IOC_IPv6_CIDR_TYPE = 4, IOC_HOST_DOMAIN_NAME_TYPE = 5, IOC_URL_TYPE = 6, IOC_FILE_HASH_TYPE = 7 | Number | Yes |
| Indicates if the value should be included (true) or excluded (false) | Boolean | Yes |
| Subtype of IoC (Subtype is -1 for all except MD5 (71) and SHA-256 (72) file hash) | Number | Yes |
Response Parameters
The following fields are returned if the request parameters are correct, otherwise error details are returned.
Field Name | Description | Data Type |
|---|---|---|
| Success status (true or false) | Boolean |
| Message | String |
| Error message | String |
| Data | String |
| Error code | Number |
Example
Request
POST https://<Manager_IP>/sdkapi/threatfeedintelligence/saveIoCValues
Payload
{
"feedId": 10,
"excludedValues": [
{
"value": "1.1.1.9",
"type": 1,
"include": false,
"subType": -1
}
]
}Response
{
"success": true,
"msg": null,
"errMsg": null,
"data": null,
"errorCode": 0
}Error Information
The following error code is returned by this URL:
S.No | Generic Error Codes | ErrorMessage | Error Reason |
|---|---|---|---|
1 | 1001 | Bad URL - HTTP 404 Not Found | Mistyped URL |
Internal Error – Null | Incorrect Input data, authentication issues |