Quantcast
Channel: THWACK: Message List
Viewing all articles
Browse latest Browse all 20396

Re: Using a Threat Intelligence Feed with LEM?

$
0
0

Right now the only real option IS the import CSV to UDG. Effectively the "Import" on a UDG can import a CSV. Mentioned here: Log & Event Manager v5.7 RC Now Available: Scheduled Searching, License Recycling, and More! - here's the copy/paste for that section (it's super brief):

 

IMPORT USER-DEFINED GROUPS FROM CSV FILES

A commonly requested feature is the ability to import CSV files to automatically populate groups, rather than having to edit data elements by hand, which we've implemented in this RC. From Build>Groups, go to (top right) Gear>Import, change to "All File Types" and choose your CSV file. The format of the file is basically what you see in Build>Groups:

UDG, UDG Name, UDG Description

Element Name, Element Data, Element Description

Element 2 Name, Element 2 Data, Element 2 Description

 

If you could get the data as a big list (text?), you could create a CSV with the other 2 columns (name/description) and pull it in. Data is the column/field that's actually used for the comparison.


Viewing all articles
Browse latest Browse all 20396

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>