Fetch TAXII feeds to use as sources
This task establishes TAXII feeds as threat intelligence sources to automatically retrieve STIX data for threat detection and analysis.
TAXII feeds provide structured threat intelligence data that can enhance your security posture by automatically updating threat indicators. If you encounter an issue during TID configuration or operation, see Troubleshoot Threat Intelligence Director.
Before you begin
Before configuring TAXII feeds, ensure your source meets the requirements in Source requirements.
Follow these steps to fetch TAXII feeds to use as sources:
Procedure
Step 1 | Choose . | ||
Step 2 | Click Add ( | ||
Step 3 | Choose | ||
Step 4 | Enter information.
| ||
Step 5 | If you want to immediately begin publishing to elements, confirm that the PUBLISH Slider ( When this option is enabled, the system automatically publishes the initial source data and any subsequent changes. For details, see Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level. | ||
Step 6 | Click Save. |
What to do next
-
TAXII feeds can contain a lot of data. It may take some time for the system to ingest all of the data. To view ingestion status, refresh the Sources page.
-
If you see an error for this source, hover over status for details.
-
If you are doing initial Threat Intelligence Director configuration, return to Set up Threat Intelligence Director.

