TI platforms

Connect Q-Feeds to EclecticIQ

Create an Incoming feed with TAXII 2.1 poll and STIX 2.1. Discovery is https://taxii.qfeeds.com/taxii2/. Use poll, not inbox.

This article follows EclecticIQ's Incoming feed, TAXII 2.1 poll documentation. TAXII needs an Enterprise licence. Credentials: Get your threat feeds.

Prerequisites

  • EclecticIQ Intelligence Center: permission to create Incoming feeds
  • Q-Feeds: Enterprise TAXII username and password
  • Network: outbound HTTPS to taxii.qfeeds.com on port 443

Q-Feeds values

EclecticIQ fieldValue
Transport typeTAXII 2.1 poll
Content typeSTIX 2.1
Auto Discoveryhttps://taxii.qfeeds.com/taxii2/
API Root URLhttps://taxii.qfeeds.com/default
Collection IDCollection UUID from discovery or the portal
Basic authenticationOn; TAXII username and password
Extra HTTP headersAccept: application/taxii+json;version=2.1 if the poll returns 406
Objects per run (max)Default 100; raise it for a large collection
Download time frameAdvancing after the first full pull

Enable Basic authentication before you search Auto Discovery. A discovery URL that requires auth will otherwise look empty.

Create the Incoming feed

  1. Create or edit an Incoming feed.
  2. Under Transport and content, set TAXII 2.1 poll and STIX 2.1.
  3. Turn on Basic authentication and enter the Q-Feeds TAXII username and password.
  4. In Auto Discovery, enter https://taxii.qfeeds.com/taxii2/ and search. Pick the collection. API Root URL and Collection ID should fill in.
  5. If they do not, paste API Root URL https://taxii.qfeeds.com/default and the collection UUID yourself.
  6. Add the Accept header under Extra HTTP headers if needed.
  7. Set Execution schedule and Objects per run. Save and run once.

Do not pick TAXII 2.1 inbox. Inbox starts a collection that listens for POST. Q-Feeds does not push into your OpenTAXII.

What an ingested indicator looks like

Q-Feeds sends atomic STIX 2.1 indicators (IPs, domains, URLs, hashes). Intelligence Center stores them as entities/observables. Search for an IP from the collection after the first successful run. You will not see threat-actor or campaign objects from this source.

Troubleshooting

  • Discovery is empty: Basic was off, or you used the API root in Auto Discovery. Discovery is /taxii2/.
  • 406 Not Acceptable: add Accept: application/taxii+json;version=2.1.
  • 403: the credentials are not Enterprise.
  • Tiny batches: Objects per run is still 100. Raise it, then leave Download time frame on Advancing.
  • Support: support@qfeeds.com or the support page.

About the EclecticIQ integration TAXII Feeds & Server

Evaluate our intelligence today!

Simplify your security operations, start your free Q-Feeds trial and experience the difference.

Activate free access