Configure Intelligence Center#
- Log in to EclecticIQ Platform. 
- Configure one or more Incoming feeds. 
- Search for intelligence of interest. - For example, search for phishing indicators in the last 24 hours. 
- Create a Dataset using the previous search query. 
Create an outgoing feed#
- In the top navigation bar, click Data configurations > Outgoing feeds > 
Step 1 - The General section#
- In the Feed name field, enter a descriptive name that is easy to remember. 
Step 2 - The Transport and content section#
- From the Transport type drop-down menu, select Syslog push. 
- From the Content type drop-down menu, select ArcSight CEF. 
- From the Datasets drop-down menu, select the dataset you created earlier. 
- From the Update strategy drop-down menu, select Append. 
- In the Syslog server host field, enter the address of your ArcSight ESM server. 
- In the Syslog server port field, enter 1514. 
- From the Protocol drop-down menu, select TCP. 
Step 3 - Schedule section#
- From the Execution schedule drop-down menu, select how often you want to run the outgoing feed task: - Set an Execution schedule to have your feed run automatically. - Option - Description - None - Default. Feeds must be manually run. - Every [n] minutes - Run this feed automatically every [n] minutes. - Select a value for [n]. - Every hour, [n] minutes past the hour - Run this feed automatically every hour + [n] minutes. - For example, setting [n] to - 4will cause this feed to run at:- 00:04
- 01:04
- etc. 
 - Every [n] hours - Run this feed automatically at the start of every [n] hours. - Select a value for [n]. - Every day at [time] - Run this feed automatically at the specified time, once a day. - Set a value for [time]. - Every [n] days - Run this feed automatically at the start of every [n] days. - Select a value for [n]. - Every week on [day of the week] at [time] - Run this feed automatically once every week, on a specific day of the week at a specific time. - Set values for [day of the week] and [time]. - Every month on [day of the month] at [time] - Run this feed automatically once every month, on a specific day of the month at a specific time. - Set values for [day of the month] and [time] - Caution - Avoid setting [day of month] to - 30or- 31. If you want a schedule to run monthly, use- 1to run at the beginning of the month instead.
Step 4 - The Processing section#
- From the Override TLP drop-down menu, select with what TLP color you want to overwrite the TLP color code associated to the outgoing feed entities. - The selected TLP value is assigned to all the entities in the outgoing feed. 
- From the Filter TLP color drop-down menu, select which entities you want to include in the outgoing feed data, based on the selected TLP value. - Only the entities that are flagged with the selected TLP color code are included in the outgoing feed. 
- From the Source reliability filter drop-down menu, select the minimum reliability level an entity must have in order to be send out in the feed 
- In the Relevancy threshold (%) field, set a filter to include in the outgoing feed data only the entities whose relevancy value is higher than the one defined here. 
- From the Allowed observable states drop-down menu, select one or more observable states to include in the outgoing feed data only the entities whose observable states match the selections defined here. 
- From the Observable types drop-down menu, select all the observable types that you want to send out in the feed. 
- From the Enrichment observable types drop-down menu, select all the observable types that you want to send out in the feed. 
- Click Save to store your changes, or Cancel to discard them.