Import data using standard format
- UpdatedJul 31, 2025
- 3 minutes to read
Upload the standard data in the supported file formats such as STIX 2.x JSON, MISP JSON.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
-
Navigate to Workspaces > Threat Intelligence Security Center.
Threat Intel Library page is displayed.
- Click Import Intelligence.
-
Click Import from standard file card.
Important: While importing the threat intelligence data in the supported file formats such as TXT, CSV, STIX 2.x JSON, MISP JSON, or Structured File, the file size is limited to 5 MB. The characters limit to raw text is limited to 10,000.
-
On the form, fill in the fields.
Field Description File Format Select the required option from the drop down list such as STIX 2.x JSON or MISP JSON. - STIX 2.x JSON: Select the format in STIX 2.x JSON to import.Note: Only Observables and Indicators will be imported from the uploaded STIX file. All the other object types will be ignored during the import process.
- MISP JSON: Select the format in MISP JSON format to import.
Upload file Click this link to upload the data in the standard file format. Set definitions TLP Select the TLP indicator from the drop-down list to be applied for the imported records. Confidence (0-100) Define the confidence value. Expiry Period (days) Enter the expiry period for the imported records. Note: This is a mandatory field.Add Tags Use the tags to annotate or ear mark records ingested into the system from this source. Start typing the tag name in the Search bar to choose the available tags in the system or enter new tag name and click Add to assign it to the source. Add Observable(s) to security Control List Select this option to add observables to the appropriate security control list. This option allows you to directly add the observables to a security control list while importing.
The available options in the drop-down list are:- Allow list
- Deny list
- None
Taxonomy Select a Taxonomy Select the taxonomy for the imported data. Using taxonomies, define dictionaries that can be used as taxonomies assigned to threat intelligence records. For example, CAPEC nomenclature. For more information, see Creating Taxonomies. Select Taxonomy values Indicates the taxonomy values that are associated with the Taxonomy. Override source value Select this check box if you wish to over ride the source values for TLP, Confidence, Expiration, Tags, and Taxonomies from the configured values. If you don't select this check box the default values are applied. - STIX 2.x JSON: Select the format in STIX 2.x JSON to import.
- Click Next.
-
Review the data before submission for processing.
Note: Reviewing of imported records is not supported for STIX option.
After you click Next, you can see the summary of all the information that user has provided in the above section, and the below section provides you with all the records that needs to be imported.
User can perform any type of activities and the multiple users can collaborate using the comment section which is available in the right contextual menu.
Note: Any records that fail the validations are skipped from the import process and those records are not displayed on the Review & submit page for further processing. - Click Update Type and select the type to update any type of the imported records.
- Click Delete to delete any type of the imported records.
-
Click Submit.
Note:
After you submit the import record, the user will be directed to the approver to approve the corresponding import record based on the approval rules configured. If the current user who is creating the record doesn't require the approval process then the record goes through the auto approval process the import job gets auto approved while submitting request.
-
Click View Status to view the status of the record or click Done.
The record displays the processed status once it is processed.
- Click Cancel to abort the import process.
- Click Go Back to go back to the previous page and review the record, if necessary.
Related Content
- Import data using structured file
Upload the structured data in the supported file formats such as CSV, XLSX or XLS.
- Import data using raw text
Import the observables data by copying and pasting raw text or entering the free text.
- Import data using unstructured file format
Upload the data in an unstructured format supported using the file formats such as TXT, CSV, JSON, XLS, XLSX.