Configuring Inbound Intel Sharing Groups
Inbound Intel Sharing Groups enable administrators to group similar inbound intelligence sharing profiles together. These groups can be used to define approval rules that apply to all profiles within the group.
Before you begin
Role required: sn_sec_tisc.admin
Procedure
Navigate to Workspaces > Threat Intelligence Security Center > Administration > Inbound Intel Sharing.
Select Inbound Intel Sharing Groups.
Select New to create Inbound Intelligence Group.
On the form, fill in the fields.
Field Description Name Name of the Inbound Intel Sharing Group. Description Description of the Inbound Intel Sharing Group. Type Specifies whether the group belongs to an internal or external organization. Select Save to save the intelligence sharing group.
Also, you can enable or disable the group based on the requirement.
Adding Group Members:
Using this section, you can attach multiple profiles to a group.
Navigate to the Group Members section.
Select Add.
The Add Inbound Intelligence Profiles dialog box is displayed. This lists all the enabled inbound intelligence sharing profiles.
Select one or more profiles.
Provide a reason for adding the selected inbound intelligence profiles to the groups.
Select Add.
The selected profiles are added to the groups.
Additionally, select Remove to remove the profiles from the group.
Note: You must add a reason for removal.
Parent Topic:Exploring Inbound Intel Sharing
Related topics
Configuring Inbound Intel Sharing Profiles
Defining Approval Rule for Inbound Intel