XSOAR Indicator Management webinar: Expired indicator and Bolt Database

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

XSOAR Indicator Management webinar: Expired indicator and Bolt Database

L5 Sessionator

**This question was asked during Part 1 of the webinar series: Indicator Management. You may review the recording here 

 

If we are using Bolt database and an indicator is expired and has a last seen date of September 1, 2023 - does that mean it exists in the September Bolt database file? If we call the indicator command and the last seen date is updated, does this move the indicator to the latest Bolt db file? We want to use XSOAR marketplace integration for Generic Export Indicator service for EDLs but are concerned about potentially losing indicators with data retention efforts, accidental removal, etc. Losing indicators for an Allow list would be dangerous.

1 accepted solution

Accepted Solutions

L5 Sessionator

A reply by @Aneesha More:

 

If we are using Bolt database and an indicator is expired and has a last seen date of September 1, 2023 - does that mean it exists in the September Bolt database file? If we call the indicator command and last seen date is updated does this move the indicator to latest Bolt db file? We want to use XSOAR marketplace integration for Generic Export Indicator service for EDLs but are concerned about potentially losing indicators with data retention efforts, accidental removal, etc. Losing indicators for an Allow list would be dangerous.

View solution in original post

1 REPLY 1

L5 Sessionator

A reply by @Aneesha More:

 

If we are using Bolt database and an indicator is expired and has a last seen date of September 1, 2023 - does that mean it exists in the September Bolt database file? If we call the indicator command and last seen date is updated does this move the indicator to latest Bolt db file? We want to use XSOAR marketplace integration for Generic Export Indicator service for EDLs but are concerned about potentially losing indicators with data retention efforts, accidental removal, etc. Losing indicators for an Allow list would be dangerous.

  • 1 accepted solution
  • 538 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!