Configure the STIX/TAXII Plugin
In Threat Exchange, go to Settings and click Plugins.
Select the GitHub plugin box to open the plugin creation pages.
Enter the Basic Information on the first page:
Configuration Name: Enter a name appropriate for your integration.
Poll Interval: Adjust to environment needs. We recommend not to go below 5 minutes for production environments.
Aging Criteria: Leave the default.
Override Reputation: Leave the default.
Enable SSL Verification: Leave the default.
Click Next.
Enter the Configuration Parameters on the second page:
STIX/TAXII Version: Select the appropriate STIX/TAXII Version from the dropdown.
Discovery URL: Enter your Discovery URL obtained earlier.
Username and Password: Enter your Username and Password (default guest/guest in case of AlienVault).
Collection Names: Enter comma separated Collection Names if you need to fetch indicators from only specific collections. Leave empty to fetch indicators from all collections..
Initial Range: Leave the default.
Type of Threat Data to Pull: Leave the default.
Click Save in the top right corner. Go to Threat Exchange > Plugins to see your new STIX/TAXII plugin.