EclecticIQ Intelligence Center
Ingest detection rules from SIEM Rules into the EclecticIQ Intelligence Center.
EclecticIQ incoming feed setup
- 1.Navigate to the incoming feed setup page
- 2.Select add new feed
- 3.You can set most fields as you wish, the key ones are
- 1.Transport type: TAXII 2.1 poll
- 2.Content type: STIX 2.1
- 5.Username: SIEM Rules username
- 6.Password: SIEM Rules API key
- 7.Added after: should be no more than 7 days because our TAXII feed does not return any more data than this
- 8.Objects per run (max): 50
- 9.Download time frame: advancing
Now click save, and you should see intelligence being ingested.
Once incoming feed is enabled, the ingested detection rules can be used in the EclecticIQ Intelligence Center.