Ingest Taxii feed into XSOAR 6.12

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Ingest Taxii feed into XSOAR 6.12

L2 Linker

Hi,

 

I am trying to ingest our taxii feed into XSOAR 6.12 with following steps:

  • installed XSOAR 6.12 on ubuntu 22.0.4 LTS
  • launched the web portal, and installed TAXII Feed (1.x) pack from marketplace
  • Ingest feed using "Integration Instance Settings"
    • Typed in the parameters such as name, discovery service URL, username/password, collection name, poll service url, first fetch time,set Feed Fetch Interval to 10 mins, etc. 
    • Test successful 

With above steps, it was able to pull indicator from the collection I specified, but, it seems every time it only pulls one indicator and the same one over and overall again, the taxii feed provides over thousands of indicators per day, but I only see one indicator on Threat Intel dashboard -> XSOAR Indicators. 

Note, I have also tested the same feeds with other platforms such as ThreatQ and ThreatConnect, from there the feeds are ingested as expected.

Could someone please advise on it?
# XSOAR6.12  #taxii integration 

16 REPLIES 16

L3 Networker

@TonyZhu  This first response only has a couple of indicators in it, but eyeballing them against the TAXII client code it seems like they should parse OK. At first I was wondering if XSOAR wasn't pulling subsequent pages of the poll response, but from the logs above it looks like it is.

 

I think you'll need Engineering and (probably) a custom debug version of the taxii client to troubleshoot this, sorry.

L2 Linker

Thanks @chrking. Really appreciate it!

 

There were lots of indicators (over thousands) in response I only kept few of them just for displaying, along with the response header.

 

Where I can get the customer debug version of the taxii client?

 

  • 3613 Views
  • 16 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!