Enabling the X-Force Threat Intelligence feed

You must enable the X-Force® Threat Intelligence feed before you can use the IBM® QRadar DNS Analyzer app.

About this task

QRadar® downloads approximately 30 MB of IP reputation data per day when you enable the X-Force Threat Intelligence feed.
Note: The error message “The IBM X-Force Threat Intelligence Feed is disabled” would be displayed if the X-Force Threat Intelligence feed is currently disabled.

Procedure

  1. Open the Admin settings:
    • In IBM QRadar V7.3.0 or earlier, click the Admin tab.
    • In IBM QRadar V7.3.1 and later, click the navigation menu (Icon for main navigation menu), and then click Admin to open the admin tab.
  2. Click System Settings.
  3. Select Yes in the Enable X-Force Threat Intelligence Feed field.
  4. Deploy changes for the new settings to take effect.
    Note: If you use a proxy server, to ensure the Enable X-Force Threat Intelligence Feed can be updated successfully, you must complete the procedures that are described in Updating X-Force data in a proxy server.

What to do next

Complete the procedures that are described in Creating an authorized service token.