Threat Intelligence Upload Indicators API "disconnected" status but data appears to be flowing

Brass Contributor

As stated in the title, the Threat Intelligence Upload Indicators API data connector has a status of disconnected but when I look at the graph for the connector, data appears to be flowing through he connector? Has anyone else experienced this issue?

 

Porter76_0-1692372876846.png

 

3 Replies

@Porter76 Have you integrated Microsoft Defender Threat Intelligence (MDTI) or any TAXII feed with sentinel? Because it happens when you connect any of these connector with sentinel it also shows the data flowing on the other connectors of TI because of the same table 'ThreatIntelligenceIndicators'

@Porter76 Glad to hear that!

 

Click Mark as Best Response & Like if my post helped you to solve your issue. This will help others to find the correct solution easily.