06-24-2025 07:03 PM
All,
I've been tasked with obtaining an alert whenever a security intelligence feed or list is added/removed/modified within Security Intelligence but only have been able to find a means to alert on events discovered from SI.
Might anyone know of a way to accomplish the above?
Many Thanks!
06-27-2025 12:23 PM
I have not tried this but myself but have you looked at the alerts function: In FMC > Settings > Add Health Alert > Pick "Threat Data Update" from the list > Security Intelligence.
Thank you for rating helpful posts!
06-29-2025 09:57 PM
@Chuck M mymilestonecardwrote:All,
I've been tasked with obtaining an alert whenever a security intelligence feed or list is added/removed/modified within Security Intelligence but only have been able to find a means to alert on events discovered from SI.
Might anyone know of a way to accomplish the above?
Many Thanks!
To alert on additions, removals, or modifications to your Security Intelligence (SI) feeds or lists, you must **monitor the internal audit or configuration change logs** of your SIEM or security platform. This involves identifying which internal log sources record administrative actions related to SI, searching for keywords like "feed," "list," "add," "modified," and then configuring your platform's native alerting mechanisms (e.g., correlation rules) to notify you of such changes. The exact steps will depend on your specific SIEM solution.
07-01-2025 09:00 AM
The SI feeds are updated constantly by Talos. By default, FMC pulls down the latest content every 2 hours.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide