How to Configure TAXII Feed Ingestion in OpenCTI: A Complete Guide

To configure TAXII feed ingestion in OpenCTI, create a dedicated source user, navigate to Data ▶ Ingestion, add a TAXII feed with the server URL and collection UUID, and set authentication to Bearer token.

OpenCTI supports automated ingestion of threat intelligence via TAXII (Trusted Automated Exchange of Intelligence Information) feeds, allowing the platform to pull collections from external servers or other OpenCTI instances. This guide explains how to configure TAXII feed ingestion using the web interface and programmatic APIs, referencing the actual implementation in the OpenCTI-Platform/opencti repository.

Prerequisites for TAXII Feed Configuration

Before configuring TAXII feed ingestion, you must prepare the user context and optional organizational attribution to ensure proper data provenance.

Create a Dedicated Source User

Create a user named [F] Source Name and add it to the Connectors group. This user becomes the User responsible for data creation for the feed, ensuring all imported objects have clear attribution in the knowledge graph.

Source: docs/docs/usage/import/taxii-feed.md

(Optional) Create a Dedicated Organization

Create an organization matching the source name and set it as the Default author for the ingestion. This attribution helps track the origin of intelligence within your threat knowledge base.

Source: docs/docs/usage/import/taxii-feed.md

Configuring TAXII Feed Ingestion via the UI

Once prerequisites are met, configure the feed through the OpenCTI web interface by mapping connection parameters to the internal schema.

Open the TAXII Ingestion Wizard

Navigate to Data ▶ Ingestion, click Add TAXII feed, and complete the form. The form fields map directly to attributes defined in ingestion-taxii.ts.

Fill the Core Connection Fields

Enter the following required parameters:

  1. TAXII server URL – The root API URL (e.g., https://example.com/taxii2/root).
  2. TAXII collection – The collection UUID (e.g., 426e3acb-db50-4118-be7e-648fab67c16c).
  3. Authentication type – Select Bearer token for private collections.
  4. Authentication value – Provide the token of a user with access to the collection.

Source: docs/docs/usage/import/taxii-feed.md

Configure Additional Options

Set the following optional fields:

  • User responsible for data creation – Select the dedicated source user created earlier.
  • Import from date – Specify the earliest added after date; leave empty to import all available objects.

Source: docs/docs/usage/import/taxii-feed.md

Save and Activate

Clicking Save creates an IngestionTaxii entity, registers a TAXII connector via registerConnectorForIngestion, and starts polling according to the platform scheduler.

Source: ingestion-taxii-domain.ts

Understanding the IngestionTaxii Schema

The IngestionTaxii object schema is defined in opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii.ts. Key attributes include:

// Attribute definitions (excerpt)
{ name: 'uri', label: 'URI', type: 'string', format: 'short', mandatoryType: 'customizable', editDefault: true, upsert: true, isFilterable: true },
{ name: 'collection', label: 'Collection', type: 'string', format: 'short', mandatoryType: 'internal', editDefault: false, upsert: true, isFilterable: true },
{ name: 'authentication_type', label: 'Authentication type', type: 'string', format: 'short', mandatoryType: 'no', editDefault: false, upsert: true, isFilterable: true },
{ name: 'added_after_start', label: 'Added after', type: 'date', mandatoryType: 'no', editDefault: true, upsert: true, isFilterable: true },

Source: ingestion-taxii.ts

Managing TAXII Feeds Programmatically

For automation and CI/CD pipelines, use the GraphQL API to manage feeds.

Adding a Feed via GraphQL

Use the ingestionTaxiiAdd mutation:

mutation AddTaxiiIngestion {
  ingestionTaxiiAdd(
    input: {
      name: "ISAC TAXII Feed"
      uri: "https://isac.example.com/taxii2/root"
      collection: "426e3acb-db50-4118-be7e-648fab67c16c"
      authentication_type: "Bearer token"
      authentication_value: "eyJhbGciOiJIUzI1NiIsIn..."
      added_after_start: "2024-01-01T00:00:00Z"
      user_id: "c0d4f3b2-9a6e-4a1e-8b6f-123456789abc"
    }
  ) {
    id
    name
    ingestion_running
  }
}

This mutation triggers addIngestion in ingestion-taxii-domain.ts.

Exporting Feed Configuration

Export configurations for backup or migration:

import { taxiiFeedExport } from './ingestion-taxii-domain';

// Assuming `taxiiIngestion` is a fetched StoreEntityIngestionTaxii
const jsonExport = await taxiiFeedExport(taxiiIngestion);
console.log(jsonExport);
// Result (pretty-printed):
/*
{
  "openCTI_version": "6.10.0",
  "type": "taxiiFeeds",
  "configuration": {
    "name": "ISAC TAXII Feed",
    "description": "Official ISAC indicator feed",
    "uri": "https://isac.example.com/taxii2/root",
    "version": "2.0",
    "collection": "426e3acb-db50-4118-be7e-648fab67c16c",
    "authentication_type": "Bearer token",
    "added_after_start": "2024-01-01T00:00:00Z"
  }
}
*/

Source: taxiiFeedExport implementation

Importing Feed Configuration

Import previously exported feeds:

mutation ImportTaxiiFeed($file: Upload!) {
  taxiiFeedAddInputFromImport(file: $file) {
    name
    uri
    collection
    authentication_type
  }
}

The resolver taxiiFeedAddInputFromImport reads the JSON file, validates the platform version (minimum 6.9.4), and returns the configuration object that can be fed into ingestionTaxiiAdd.

Source: taxiiFeedAddInputFromImport resolver and domain logic (lines 91-103)

Resetting Ingestion State

Clear the cursor to force a fresh pull:

mutation ResetTaxiiState($id: ID!) {
  ingestionTaxiiResetState(id: $id) {
    id
    name
    current_state_cursor
    added_after_start
  }
}

Calls ingestionTaxiiResetState, which clears the cursor via patchTaxiiIngestion in ingestion-taxii-domain.ts.

Source: ingestionTaxiiResetState

Key Source Files and Implementation Details

File Role Link
docs/docs/usage/import/taxii-feed.md End-user documentation for configuring TAXII feeds View
ingestion-taxii.ts Schema definition for the IngestionTaxii internal object (attributes, identifiers) View
ingestion-taxii-domain.ts Business logic: create, edit, delete, reset, export, import, and connector registration View
ingestion-taxii-resolver.ts GraphQL resolvers that expose the domain functions to the API View
ingestion-taxii-collection.graphql GraphQL schema for the TAXII collection UI (queries, mutations) View

Summary

  • Create dedicated users and organizations before configuring feeds to ensure proper data attribution and access control.
  • Configure TAXII feed ingestion via Data ▶ Ingestion in the UI by providing the server URL, collection UUID, and Bearer token authentication.
  • Understand the schema defined in ingestion-taxii.ts, which controls mandatory fields like uri and collection and optional fields like added_after_start.
  • Manage feeds programmatically using GraphQL mutations for adding (ingestionTaxiiAdd), exporting (taxiiFeedExport), importing (taxiiFeedAddInputFromImport), and resetting state (ingestionTaxiiResetState).
  • Reset state when you need to force a fresh pull by clearing the current_state_cursor via the reset mutation.

Frequently Asked Questions

What authentication types does OpenCTI support for TAXII feeds?

OpenCTI supports Bearer token authentication for private TAXII collections, as defined in the authentication_type field of the IngestionTaxii schema. You provide the token in the authentication_value field when configuring the feed via the UI or GraphQL API.

How do I force a TAXII feed to re-import all data from the beginning?

Use the Reset button in the UI or call the ingestionTaxiiResetState GraphQL mutation. This clears the current_state_cursor via patchTaxiiIngestion in ingestion-taxii-domain.ts, forcing the connector to poll the collection from the start date or from the beginning if no date is specified.

Can I migrate TAXII feed configurations between OpenCTI instances?

Yes. Use the taxiiFeedExport function to generate a JSON file containing the feed configuration and platform version. Then use the taxiiFeedAddInputFromImport mutation to import it into another instance. The import logic validates platform version compatibility (minimum version 6.9.4) before processing.

Where is the TAXII ingestion logic implemented in the OpenCTI codebase?

The core logic resides in opencti-platform/opencti-graphql/src/modules/ingestion/ingestion-taxii-domain.ts, which handles creation, updates, resets, exports, and imports. The schema definition is in ingestion-taxii.ts, and GraphQL resolvers are in ingestion-taxii-resolver.ts.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →