Re-importing Observable Values

ThreatStream enables you to re-import observable values that were previously imported by your organization via the ThreatStream UI.

Re-importing observable values can be helpful in the following cases:

  • Changing the Status of inactive observables to Active

  • Updating details of existing observables

Any time you approve an import job that contains observables previously imported by your organization, ThreatStream merges certain details of newly imported observables into the details of existing observables.

Visibility of Re-imported Observables

Following re-import merges, observables are always made active and assigned the visibility setting that allows for the widest visibility. For example, if the existing observable is private to your organization and the newly imported observable is restricted to specific Trusted Circles, the observable will be shared with the selected Trusted Circles as a result of the merge. If both instances of the observable are shared with different Trusted Circles, both groups of Trusted Circles are given access to the observable as a result of the merge.

However, existing observables whose visibility is set to My Organization can only be re-imported with the same visibility or shared with Trusted Circles. Observables that are private to your organization can not be made public to the Anomali Community as a result of re-import merges. In these cases, the observables you attempt to import are excluded from import jobs.

Likewise, existing observables shared with the Anomali Community cannot be restricted to your organization or Trusted Circles as a result of re-import merges. In these cases, a distinct instance of the observable is imported and made active with the more restrictive Visibility setting you selected.

The figure below illustrates how observable visibility can be expanded as a result of re-import merges.

Note: If you attempt to re-import Organization or Trusted Circle observables with the Anomali Community visibility setting, they will be excluded from the import job.

Results of Re-import Merges

Existing values from all other fields are overwritten by new values with the exception of the fields listed in the following table.

Field Effect of Merge on Existing Values
Associations Combined with associations from newly imported observable
Comments Existing comments maintained
Source Combined with source listed for newly imported observable
Tags Combined with tags from newly imported observable

Note: Merges do not occur in cases of existing observables not owned by your organization. In these cases, a distinct instance of the observable is imported and made active.