Upload a local file to use as a source
This task allows you to manually upload a local STIX or flat file to create threat intelligence indicators in Threat Intelligence Director.
Use this procedure for a one-time manual upload of a local file.
When ingesting a STIX file, Threat Intelligence Director creates a simple or complex indicator from the contents of the STIX file.
When ingesting a flat file, Threat Intelligence Director creates a simple indicator for each observable value in the file.
If you encounter an issue during Threat Intelligence Director configuration or operation, refer to Troubleshoot Threat Intelligence Director
Procedure
Step 1 | Make sure your file meets the requirements in Source requirements | ||
Step 2 | Choose . | ||
Step 3 | Click Add ( | ||
Step 4 | Choose Upload as the Delivery method for the source. | ||
Step 5 | Complete the form.
| ||
Step 6 | If you want to immediately begin publishing to elements, confirm that the Publish Slider ( If you do not publish the source at ingestion, you cannot publish all source indicators at once later; instead, you must publish each observable individually. See Pause or publish Threat Intelligence Director data at the source, indicator, or observable Level. | ||
Step 7 | Click Save. |
What to do next
-
To view ingestion status, refresh the Sources page. If you see an error, hover over status for details.
-
If you are doing initial Threat Intelligence Director configuration, return to Set up Threat Intelligence Director.

