View and manage indicators

This task enables you to view current indicators and manage their configuration settings including actions and publish status.

Indicators are generated automatically from ingested sources. For more information about the contents of this page, refer to Indicator summary information.

Procedure


Step 1

Choose Integrations > + Show more > Threat intelligence director > Sources.

Step 2

Click Indicators.

Step 3

View your current indicators.

  • To filter the indicators displayed on the page, click Filter (filter icon). For more information, refer to Filter Threat Intelligence Director data in table views.

  • To view additional details about an indicator, including associated observables, click the indicator name. For more information, refer to Indicator details.

  • In the Incidents column, click the number to view information about incidents associated with an indicator, or hover the cursor over Incidents to view whether the incidents are fully realized or partially realized.

  • To determine whether Threat Intelligence Director finished ingesting an indicator from the source, view the Status column.

Step 4

Manage your current indicators.