Source Summary Information

The Sources page displays summary information for all configured sources. The table below provides brief descriptions of the fields in the summary display. For detailed information on these fields, see descriptions in the relevant configuration topic for the source: See Options for Ingesting Data Sources.

Sources Summary Information

Field

Description

Name

The source name.

Type

The data format of the source (STIX or Flat File).

Delivery

The method threat intelligence director uses to retrieve the source.

Action

The action (Block or Monitor) that the system is configured to perform on traffic matching the data contained within this source.

For more information about threat intelligence director actions, including availability, inheritance, and overriding inheritance, see Factors That Affect the Action Taken.

Publish

On or Off toggle specifying whether threat intelligence director publishes data from the source to registered elements (managed devices configured to support threat intelligence director).

Indicators can inherit Publish settings from a parent source, and observables can inherit Publish settings from a parent indicator. For more information, see Inheritance in Threat Intelligence Director Configurations.

Last Updated

The date and time threat intelligence director last updated the source.

Status

The current status of the source:

  • New—The source is newly created.

  • Scheduled—The initial download or subsequent update is scheduled, but not yet in progress.

  • Downloadingthreat intelligence director is performing the initial download or update refresh.

  • Parsing or Processingthreat intelligence director is ingesting the source.

  • Completedthreat intelligence director finished ingesting the source.

  • Completed with Errorsthreat intelligence director finished ingesting the source, but some observables are unsupported or invalid.

  • Errorthreat intelligence director experienced a problem. If the source is a TAXII or URL source with an Update Frequency specified, and updates are not paused, threat intelligence director retries on the next scheduled update.

Refresh the page to update the status.

Edit (edit icon)

Clicking this icon allows you to edit settings for the source.

Delete (delete icon)

Clicking this icon permanently deletes the source.