How to Configure TAXII Feed Ingestion in OpenCTI: A Complete Guide
To configure TAXII feed ingestion in OpenCTI, create a dedicated source user, navigate to Data ▶ Ingestion, add a TAXII feed with the server URL and collection UUID, and set authentication to Bearer token.
OpenCTI supports automated ingestion of threat intelligence via TAXII (Trusted Automated Exchange of Intelligence Information) feeds, allowing the platform to pull collections from external servers or other OpenCTI instances. This guide explains how to configure TAXII feed ingestion using the web interface and programmatic APIs, referencing the actual implementation in the OpenCTI-Platform/opencti repository.
Prerequisites for TAXII Feed Configuration
Before configuring TAXII feed ingestion, you must prepare the user context and optional organizational attribution to ensure proper data provenance.
Create a Dedicated Source User
Create a user named [F] Source Name and add it to the Connectors group. This user becomes the User responsible for data creation for the feed, ensuring all imported objects have clear attribution in the knowledge graph.
Source: docs/docs/usage/import/taxii-feed.md
(Optional) Create a Dedicated Organization
Create an organization matching the source name and set it as the Default author for the ingestion. This attribution helps track the origin of intelligence within your threat knowledge base.
Source: docs/docs/usage/import/taxii-feed.md
Configuring TAXII Feed Ingestion via the UI
Once prerequisites are met, configure the feed through the OpenCTI web interface by mapping connection parameters to the internal schema.
Open the TAXII Ingestion Wizard
Navigate to Data ▶ Ingestion, click Add TAXII feed, and complete the form. The form fields map directly to attributes defined in ingestion-taxii.ts.
Fill the Core Connection Fields
Enter the following required parameters:
- TAXII server URL – The root API URL (e.g.,
https://example.com/taxii2/root). - TAXII collection – The collection UUID (e.g.,
426e3acb-db50-4118-be7e-648fab67c16c). - Authentication type – Select Bearer token for private collections.
- Authentication value – Provide the token of a user with access to the collection.
Source: docs/docs/usage/import/taxii-feed.md
Configure Additional Options
Set the following optional fields:
- User responsible for data creation – Select the dedicated source user created earlier.
- Import from date – Specify the earliest
added afterdate; leave empty to import all available objects.
Source: docs/docs/usage/import/taxii-feed.md
Save and Activate
Clicking Save creates an IngestionTaxii entity, registers a TAXII connector via registerConnectorForIngestion, and starts polling according to the platform scheduler.
Source: ingestion-taxii-domain.ts
Understanding the IngestionTaxii Schema
The IngestionTaxii object schema is defined in opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts. Key attributes include:
// Attribute definitions (excerpt)
{ name: 'uri', label: 'URI', type: 'string', format: 'short', mandatoryType: 'customizable', editDefault: true, upsert: true, isFilterable: true },
{ name: 'collection', label: 'Collection', type: 'string', format: 'short', mandatoryType: 'internal', editDefault: false, upsert: true, isFilterable: true },
{ name: 'authentication_type', label: 'Authentication type', type: 'string', format: 'short', mandatoryType: 'no', editDefault: false, upsert: true, isFilterable: true },
{ name: 'added_after_start', label: 'Added after', type: 'date', mandatoryType: 'no', editDefault: true, upsert: true, isFilterable: true },
Source: ingestion-taxii.ts
Managing TAXII Feeds Programmatically
For automation and CI/CD pipelines, use the GraphQL API to manage feeds.
Adding a Feed via GraphQL
Use the ingestionTaxiiAdd mutation:
mutation AddTaxiiIngestion {
ingestionTaxiiAdd(
input: {
name: "ISAC TAXII Feed"
uri: "https://isac.example.com/taxii2/root"
collection: "426e3acb-db50-4118-be7e-648fab67c16c"
authentication_type: "Bearer token"
authentication_value: "eyJhbGciOiJIUzI1NiIsIn..."
added_after_start: "2024-01-01T00:00:00Z"
user_id: "c0d4f3b2-9a6e-4a1e-8b6f-123456789abc"
}
) {
id
name
ingestion_running
}
}
This mutation triggers addIngestion in ingestion-taxii-domain.ts.
Exporting Feed Configuration
Export configurations for backup or migration:
import { taxiiFeedExport } from './ingestion-taxii-domain';
// Assuming `taxiiIngestion` is a fetched StoreEntityIngestionTaxii
const jsonExport = await taxiiFeedExport(taxiiIngestion);
console.log(jsonExport);
// Result (pretty-printed):
/*
{
"openCTI_version": "6.10.0",
"type": "taxiiFeeds",
"configuration": {
"name": "ISAC TAXII Feed",
"description": "Official ISAC indicator feed",
"uri": "https://isac.example.com/taxii2/root",
"version": "2.0",
"collection": "426e3acb-db50-4118-be7e-648fab67c16c",
"authentication_type": "Bearer token",
"added_after_start": "2024-01-01T00:00:00Z"
}
}
*/
Source: taxiiFeedExport implementation
Importing Feed Configuration
Import previously exported feeds:
mutation ImportTaxiiFeed($file: Upload!) {
taxiiFeedAddInputFromImport(file: $file) {
name
uri
collection
authentication_type
}
}
The resolver taxiiFeedAddInputFromImport reads the JSON file, validates the platform version (minimum 6.9.4), and returns the configuration object that can be fed into ingestionTaxiiAdd.
Source: taxiiFeedAddInputFromImport resolver and domain logic (lines 91-103)
Resetting Ingestion State
Clear the cursor to force a fresh pull:
mutation ResetTaxiiState($id: ID!) {
ingestionTaxiiResetState(id: $id) {
id
name
current_state_cursor
added_after_start
}
}
Calls ingestionTaxiiResetState, which clears the cursor via patchTaxiiIngestion in ingestion-taxii-domain.ts.
Source: ingestionTaxiiResetState
Key Source Files and Implementation Details
| File | Role | Link |
|---|---|---|
docs/docs/usage/import/taxii-feed.md |
End-user documentation for configuring TAXII feeds | View |
ingestion-taxii.ts |
Schema definition for the IngestionTaxii internal object (attributes, identifiers) |
View |
ingestion-taxii-domain.ts |
Business logic: create, edit, delete, reset, export, import, and connector registration | View |
ingestion-taxii-resolver.ts |
GraphQL resolvers that expose the domain functions to the API | View |
ingestion-taxii-collection.graphql |
GraphQL schema for the TAXII collection UI (queries, mutations) | View |
Summary
- Create dedicated users and organizations before configuring feeds to ensure proper data attribution and access control.
- Configure TAXII feed ingestion via Data ▶ Ingestion in the UI by providing the server URL, collection UUID, and Bearer token authentication.
- Understand the schema defined in
ingestion-taxii.ts, which controls mandatory fields likeuriandcollectionand optional fields likeadded_after_start. - Manage feeds programmatically using GraphQL mutations for adding (
ingestionTaxiiAdd), exporting (taxiiFeedExport), importing (taxiiFeedAddInputFromImport), and resetting state (ingestionTaxiiResetState). - Reset state when you need to force a fresh pull by clearing the
current_state_cursorvia the reset mutation.
Frequently Asked Questions
What authentication types does OpenCTI support for TAXII feeds?
OpenCTI supports Bearer token authentication for private TAXII collections, as defined in the authentication_type field of the IngestionTaxii schema. You provide the token in the authentication_value field when configuring the feed via the UI or GraphQL API.
How do I force a TAXII feed to re-import all data from the beginning?
Use the Reset button in the UI or call the ingestionTaxiiResetState GraphQL mutation. This clears the current_state_cursor via patchTaxiiIngestion in ingestion-taxii-domain.ts, forcing the connector to poll the collection from the start date or from the beginning if no date is specified.
Can I migrate TAXII feed configurations between OpenCTI instances?
Yes. Use the taxiiFeedExport function to generate a JSON file containing the feed configuration and platform version. Then use the taxiiFeedAddInputFromImport mutation to import it into another instance. The import logic validates platform version compatibility (minimum version 6.9.4) before processing.
Where is the TAXII ingestion logic implemented in the OpenCTI codebase?
The core logic resides in opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts, which handles creation, updates, resets, exports, and imports. The schema definition is in ingestion-taxii.ts, and GraphQL resolvers are in ingestion-taxii-resolver.ts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →