- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-02-2023 11:34 AM
Hi,
I am trying to ingest our taxii feed into XSOAR 6.12 with following steps:
With above steps, it was able to pull indicator from the collection I specified, but, it seems every time it only pulls one indicator and the same one over and overall again, the taxii feed provides over thousands of indicators per day, but I only see one indicator on Threat Intel dashboard -> XSOAR Indicators.
Note, I have also tested the same feeds with other platforms such as ThreatQ and ThreatConnect, from there the feeds are ingested as expected.
Could someone please advise on it?
# XSOAR6.12 #taxii integration
11-09-2023 10:25 PM
@TonyZhu This first response only has a couple of indicators in it, but eyeballing them against the TAXII client code it seems like they should parse OK. At first I was wondering if XSOAR wasn't pulling subsequent pages of the poll response, but from the logs above it looks like it is.
I think you'll need Engineering and (probably) a custom debug version of the taxii client to troubleshoot this, sorry.
11-13-2023 08:57 AM
Thanks @chrking. Really appreciate it!
There were lots of indicators (over thousands) in response I only kept few of them just for displaying, along with the response header.
Where I can get the customer debug version of the taxii client?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!