Security Compliance
Enable or Disable Threat Feeds
This article describes how to enable or disable Threat Feeds. Security Event Manager (formerly Log & Event Manager) 6.2 introduced the feature of Threat Feeds, which allow recognizing known and proven threats. Rules can make use of this data to automatically take action on Threat Feeds.
First published date
Last published date
Overview
This article describes how to enable or disable Threat Intelligence feeds. SEM (versions 6.2 & newer) introduced the feature of Threat Intelligence feeds, which allow recognizing known and proven threats. Rules can make use of this data to automatically take action on Threat Intelligence feeds.
Other references:
Product section
Resolution
- Log onto the SEM Web or Air Console.
- Click Manage > Appliances.
- Go to the Settings tab and select or deselect Allow Log & Event Manager to detect threats based on lists of known malicious IP addresses.
- To verify that your Threat Intelligence feed is updating every morning, you can run the following nDepth search and look for this recurring event that comes in every morning at 3:14 AM:
InternalInfo.EventInfo = *threat*
Enable the Threat Intelligence feed in the SEM Events Console:
- In the SEM Events Console, click the settings button.
- On the Settings page, click the Threat Intelligence tab.
- Toggle the button to allow SEM to enable the Threat Intelligence feed.
- In the Events viewer, search for threat to verify the threat intelligence feed is updating.
Note: Only administrators have permissions to enable or disable the Threat Intelligence feed. Disabling and re-enabling the Threat Intelligence feed forces a Threat Intelligence update and creates an InternalAudit event. Restarting SEM also forces the Threat Intelligence feed to update.