Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level
This task allows you to control the publishing of Threat Intelligence Director data by pausing or enabling publication at the source, indicator, or observable level.
If publishing is enabled at the Source level, the system automatically publishes the initial source data and any subsequent changes including:
-
changes from periodic source refreshes
-
changes resulting from system action (for example, TTL expiration)
-
any user-initiated changes (for example, a change in the Action setting for an indicator or observable)
Note | To purge all Threat Intelligence Director observables at once from your devices (elements), see Pause Threat Intelligence Director and purge Threat Intelligence Director data from elements. |
Before you begin
Before pausing publishing, review the ramifications described in Pausing publishing.
Procedure
Step 1 | Choose any of these options.
|
Step 2 | Locate the Publish Slider ( |
Step 3 | (Observables only) If you want to resume inheriting the publication setting from the parent indicator, click Revert next to the Publish setting for the observable. |
What to do next
-
Wait at least ten minutes for elements to receive changes. Changes involving large sources will take longer.
-
(Optional) Change the publication frequency for TID data at the observable level. Refer to Modify the observable publication frequency.
