Configure Threat Intelligence Source
Configure the threat intelligence providers for IP address, URL, file hash to confirm the maliciousness of the reported event.
To configure the threat intelligence source:
- Select Administration > Insights Management > Threat Intelligence.
The Threat Intelligence page appears.
- Click the plus icon (+).
The Create Configuration page appears.
- Complete the configuration according to the guidelines provided in Table 1.
- Click OK.
A new threat intelligence source is configured and listed on the Threat Intelligence page.
Table 1: Configure Threat Intelligence Source
Select the threat intelligence providers from the list. The supported threat intelligence providers are IBM X-Force, VirusTotal, and OPSWAT Metadefender.
Enter a valid API key to look up the threat intelligence provider’s APIs.
Enter a password, if you using IBM X-Force, to look up the threat intelligence provider’s APIs.