Verisign iDefense is a closed-source threat intelligence feed available to all Lumeta customers. This feed correlates iDefense IPs against your network's IPs to produce actionable lists of zombie devices and threat flows in your network.
To use iDefense, you'll need the iDefense license key provided by Lumeta. Look for this key in the original welcome email message you received from Lumeta Support. If you can't find your iDefense key, please contact us.
To show the zombie devices in your network, you do not need NetFlow data. This dashboard is generated using native Lumeta-indexed data. The iDefense feed is correlated against NetFlow data. The intersection of the two populates the threat_feed_ip table. Browse to Settings > Tables > threat_feed_ip > View to open the table. |
To configure the feed . . .
Enable NetFlowThe NetFlow-capture service enables your Lumeta Command Center to ingest NetFlow data. To enable NetFlow capture from the Lumeta GUI:
To enable NetFlow capture from the Lumeta command-line interface:
Configure the iDefense feed as follows:
|