Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ChruNDC
Explorer

Import Indicator file CSV [R80.40] API (1.6]

Hello

I want to block a list of ip with the indicator function. For this I go to Theart Prevention -> Indicators -> Import file and the file is imported.

Every day I have to push a new file and delete the old one. So I would like to use checkpoint APIs to do this.

I manage to delete the file but I can't find how to import the file.

Can you help me ?

Thanks

 

0 Kudos
6 Replies
Art_Zalenekas
Employee
Employee

0 Kudos
ChruNDC
Explorer

I get a list of IPs to block every day. I already have a script in python that converts this list of ip to checkpoint format to import. The goal is to have a single script that will create the file, delete the old one and add the new one. And using the checkpoint APIs seems consistent to me.

I'm new to checkpoint so I don't know the features yet, but thanks for the feedback, I'll take a look.

0 Kudos
genisis__
Advisor

Look forward to the finished results.

pfilipe
Participant

Hello ChruNDC,

 

Could you provide the CSV file or the format?

I am trying to import a CSV through smart console but i keep getting the error "Indicator in row 1 has less fields than expected".

Already tried to use an example of checkpoint but still no success.

 

Thanks 

0 Kudos
Nir_Naaman
Employee
Employee

Have you considered using sk132193 Custom Intelligence Feeds? Instead of pushing policy from your management, you can configure your gateways to pull indicators from a feed. When the feed contents change, the gateway automatically stops blocking the old values and starts blocking the new. And, if you're looking for a managed facility, you could automate the input feed on Infinity NDR, and configure your gateways to pull from there.

Note that an R80.40 gateway will not match IP IOCs to source IP, only destination IP. R81 and higher block in both directions. This is true regardless of whether you're pushing policy or pulling from the gateway.

pfilipe
Participant

Hello nir_Naaman,

 

Yes i already consider but the customer what to be managed by the MGMT and Centralized.

 

0 Kudos