EDL
Use the Generic Export Indicators Service integration to provide an endpoint with a list of indicators as a service for the system indicators.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- EDL
Configuration parameters
- on_demand — Update list on demand only
- indicators_query — Indicator Query
- format — Outbound Format
- fields_filter — Exported Fields
- edl_size — List Size
- cache_refresh_rate — Refresh Rate
- certificate — Certificate (Required for HTTPS)
- key — Private Key (Required for HTTPS)
- cache_lock_timeout — Cache Lock Timeout (Deprecated)
- cache_lock_age — Cache Lock Age (Deprecated)
- cache_404_ttl — Cache 404 TTL
- cache_default_ttl — Cache Default TTL
- credentials — Username
- longRunningPort — Listen Port (required)
- add_comment_if_empty — Add comment to empty list
- url_port_stripping — Strip ports from URLs
- url_protocol_stripping — Strip protocols from URLs
- url_truncate — Truncate URL length
- enforce_ascii — Enforce ASCII only
- prepend_string — Prepend string to list
- append_string — Append string to list
- collapse_ips — IP Collapsing
- maximum_cidr_size — Maximum Size of CIDR Block (by mask bit)
- no_wildcard_tld — Exclude top level domainGlobs
- drop_invalids — PAN-OS: drop invalid URL entries
- hsts_header — Add HSTS header
- mwg_type — McAfee Gateway: Indicator List Type
- category_default — Symantec ProxySG: Default Category
- category_attribute — Symantec ProxySG: Listed Categories
- csv_text — Show CSV format as Text
- page_size — XSOAR Indicator Page Size
- longRunning — Long Running Instance
- nginx_global_directives — NGINX Global Directives
- nginx_server_conf — NGINX Server Conf
- timeout — NGINX Read Timeout
- use_legacy_query — Advanced: Use Legacy Queries
- extensive_logging — Extensive Logging
Commands (2)
- edl-update — Updates values stored in the EDL (only available On-Demand).
- export-indicators-list-update — Updates values stored in the List (only available On-Demand).