- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Importing Indicator Error "Indicator in row 1 ...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Importing Indicator Error "Indicator in row 1 has less fields than expected"
Hello,
I am trying to Import a External CSV File to Checkpoint Indicators but getting the error "Indicator in row 1 has less fields than expected".
Already tried with Checkpoint examples as seen on https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut.... But no success.
Could somone provide me an CSV that works to see what is the correct syntax and to see if i keep getting the error?
Best regards.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am using this exact template for our IOC feed on R81 management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may want to have TAC help you with this, as I saw someone post same problem before on here, but there was no solution. Personally, I had never tried this before, so wont even try give you a suggestion, sorry.
Though, if you can provide me with your CSV file and steps you used to import it, Im happy to try it in my lab and report back.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Will Open a TAC case then. If i get any developments will post here.
Thanks anyway!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @pfilipe,
Have you had a response from TAC? I'm getting this error when importing an IOC CSV file into R80.40 SmartConsole. Interested to see if TAC have given you any advice/example CSVs.
Thanks,
Aaron.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Aaron,
I found the correct Syntax it needs to have all the fields Uniq-Name,value,Type,Confidence,Severity,Product,Comment.
Where Value is the IP/URL/DOMAIN you want to block. Like this!
domain1,google.com,Domain,high,high,AV,Domain
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's great! Thanks for that 😊
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
Yes, this is for hashes for example.
The syntax is Uniq-Name,value,Type,Confidence,Severity,Product,Comment.
Product are AV - Antivirus and AB-AntiBot.
The comment is not Mandatory and can be null. If you want to use an IP for example:
IP1,192.168.1.1,IP,high,high,AB,
Best regards,
PF
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Pfilipe,
Many thanks for the feedback, however was try import the file you gave thru smartconsole still encounter the same error.
Is that any syntax need to add in order to import?
Best Regards,
W
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That is weird. Because i have the exact same file implemented on a checkpoint in R81.10. Only if checkpoint changed the syntax somehow...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I am using this exact template for our IOC feed on R81 management
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Many thanks the file, is work perfectly.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I am happy to see the issue was resolved.
Loading IOC CSV is based on using Check Point's template.
more information can be found in sk132193
in R81.10 presents new IOC capabilities that allows IOC configuration using a simple menu which will include custom feeds as well
