<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Default Action Supported for Third-party integration feeds in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5269621#M1119981</link>
    <description>&lt;P&gt;I believe I have found the answer to my own question.&lt;/P&gt;&lt;P&gt;In FMC if you go to Integration&amp;gt;Sources and then click on the + in the upper right corner, it brings up the Add Source window.&lt;/P&gt;&lt;P&gt;If you change Delivery to Upload, Type to Flat File, the action drop-down is no longer greyed out.&lt;/P&gt;&lt;P&gt;The supported file type is .txt. You will have to upload multiple files if you want to block different observable types. One file per observable type (i.e. IPv4, Domain, URL, SHA-256, etc.)&lt;/P&gt;</description>
    <pubDate>Mon, 10 Mar 2025 17:54:12 GMT</pubDate>
    <dc:creator>MatthewHickey7355</dc:creator>
    <dc:date>2025-03-10T17:54:12Z</dc:date>
    <item>
      <title>Default Action Supported for Third-party integration feeds</title>
      <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5268817#M1119927</link>
      <description>&lt;P&gt;My organization is ingesting third-party intelligence feeds into our FMC via STIX/TAXII. A default action of block is not supported for this delivery method. Because ours is a sparsely staffed team who fills many widely ranging IT roles, and the feeds we ingest often contain several thousands of observables, we can't feasibly keep up with the manual process of clicking each one and setting it to block. Can anybody confirm if there is a way to bulk edit observables under Integration&amp;gt;Sources&amp;gt;Observables? Or can switching from STIX/TAXII to ingesting a flat file help us get around not being able to block by default?&lt;/P&gt;&lt;P&gt;TAC, while usually helpful, hasn't been able to give me a straight answer and neither can Google. I see in some places on the web that a default block action is supported, and in other places straight-up contradictions of that.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 20:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5268817#M1119927</guid>
      <dc:creator>MatthewHickey7355</dc:creator>
      <dc:date>2025-03-07T20:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Supported for Third-party integration feeds</title>
      <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5268864#M1119931</link>
      <description>&lt;P&gt;This is not possible:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/threat-intelligence-director.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/770/management-center-device-config-77/threat-intelligence-director.html&lt;/A&gt;&lt;/P&gt;
&lt;PRE class="p"&gt;You cannot change the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;selection for TAXII sources.&lt;BR /&gt;&lt;SPAN&gt;Block&amp;nbsp;&lt;/SPAN&gt;is not an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Action&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;option for TAXII sources, as STIX data can contain complex indicators, &lt;BR /&gt;which the system cannot block. Devices (elements) store and take action based on single observables; &lt;BR /&gt;they cannot take action based on multiple observables.&lt;/PRE&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Mar 2025 23:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5268864#M1119931</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2025-03-07T23:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Supported for Third-party integration feeds</title>
      <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5269461#M1119964</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks, but I already knew you can't change the default action for STIX/TAXII sources. Which is why I posted this thread. I'm asking if there is any way to bulk edit them instead of having to do them all individually. OR will ingesting them with a flat format .txt file allow us to default the action to block?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 11:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5269461#M1119964</guid>
      <dc:creator>MatthewHickey7355</dc:creator>
      <dc:date>2025-03-10T11:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Supported for Third-party integration feeds</title>
      <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5269621#M1119981</link>
      <description>&lt;P&gt;I believe I have found the answer to my own question.&lt;/P&gt;&lt;P&gt;In FMC if you go to Integration&amp;gt;Sources and then click on the + in the upper right corner, it brings up the Add Source window.&lt;/P&gt;&lt;P&gt;If you change Delivery to Upload, Type to Flat File, the action drop-down is no longer greyed out.&lt;/P&gt;&lt;P&gt;The supported file type is .txt. You will have to upload multiple files if you want to block different observable types. One file per observable type (i.e. IPv4, Domain, URL, SHA-256, etc.)&lt;/P&gt;</description>
      <pubDate>Mon, 10 Mar 2025 17:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5269621#M1119981</guid>
      <dc:creator>MatthewHickey7355</dc:creator>
      <dc:date>2025-03-10T17:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Default Action Supported for Third-party integration feeds</title>
      <link>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5341554#M1123266</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/874769"&gt;@MatthewHickey7355&lt;/a&gt;&amp;nbsp;What's the benefit of doing the flat file the way you describe vs. creating a security intelligence list object and and adding to the Security Intelligence section of the Access Control Policy?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 16:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/default-action-supported-for-third-party-integration-feeds/m-p/5341554#M1123266</guid>
      <dc:creator>Danny Dulin</dc:creator>
      <dc:date>2025-10-23T16:02:37Z</dc:date>
    </item>
  </channel>
</rss>

