Viewing and Monitoring Health Information of Active Feeds and Intelligence Channels

ThreatStream allows you to view and monitor the current status of your active channels (feeds and intelligence channels)  in the APP Store.

Note: To view health information, you must be in the list view of APP Store.

To view health information of a feed or intelligence channel:

  1. Navigate to ThreatStream > APP Store > APP Store.

  2. In the right corner above the Actions menu, click the list view.

  3. Click the name or the status icon of an activated feed or intelligence channel. The window that opens displays the current state of all sources (channels) in a feed.

    The History column shows the synchronization history of all sources from the last 30 days. The Last Run column shows the last time each source was synchronized. The Interval column shows approximately how often each source is synchronized. The Health column may show the following information:

  • : The channel is synchronizing with ThreatStream as expected.

  • : The channel is not synchronizing with ThreatStream as expected. If the feed uses credentialed activation, verify that your credentials are up to date. See Credential Feed Activation for a list of credentialed feeds.

  • : The channel is active, but ThreatStream has not yet synchronized data from the source.

If the feed is credentialed, the feed health information is displayed on the Health tab of the resulting window, as shown in the following example.

Depending on the number of successful synchronization requests per day, the health status of the channel on a particular date is listed as follows:

  • : All synchronization requests were successful on a particular date.

  • : At least 1 but less than 20% synchronization requests returned errors on a particular date.

  • : At least 20% of synchronization requests returned errors on a particular date.

  • : There was no requests on a particular date.

You can hover over a date to view detailed information on channel synchronization.

Note:
  • It is not unusual for some channels to encounter temporary errors over the course of a 30-day period. These errors generally occur due to service availability from vendors and are resolved after a short period. Contact Anomali Customer Support if a channel consistently reports a high error count for more than 24 hours.
  • The Interval column is only an estimate of how frequently each channel is synchronized. The actual frequency may vary depending on how many channels are being synchronized simultaneously.

To receive an email or in-app notification when a feed or intelligence channel is down:

  1. Select Error Notifications.

  2. Set the frequency of channel error notifications by selecting one of the values from the No Data Threshold drop-down list. The list of frequency values varies and is based on a channel type. You can either select the value recommended by Anomali, or the value that meets your organization's needs best. The recommended value is based on the historical frequency of data ingestion into a channel. By default, the frequency value is set to Never.


  3. Click Save Changes.

    For more information about notifications in ThreatStream, see Receiving Notifications from ThreatStream.