- Native TAXII import, built into recent OpenCTI versions. Use this when your version supports it.
- The legacy external-import TAXII2 connector, for older versions that don’t yet include native TAXII import.
Prerequisites
Before you connect OpenCTI to Pulsedive, make sure you have:- A Pulsedive account and API key. Find your API key on your Pulsedive account page.
- A Pulsedive Pro or Feed plan to access the Indicator and Threat collections. The free Test collection works with any account, so you can evaluate the integration first.
- An OpenCTI instance you can administer.
- For the legacy path, the ability to deploy a connector and set its environment variables.
Connecting OpenCTI to Pulsedive with Native TAXII Import
OpenCTI’s built-in TAXII ingester polls Pulsedive and imports each collection you configure. A TAXII ingester imports one collection, so configure one ingester per Pulsedive collection.- In OpenCTI, go to Data, then Ingestion.
- Select the TAXII Feeds tab.
- Create a new TAXII feed ingester.
- Enter details for the ingester:
- Select the user responsible for the imported data. A dedicated import user keeps the source traceable.
- Optionally, set an import-from date to limit how far back OpenCTI retrieves data.
- Save the ingester, then start it from the burger menu.
Connecting OpenCTI to Pulsedive with the Legacy Connector
If your OpenCTI version doesn’t include native TAXII import, deploy the external-import TAXII2 connector and configure it with these environment variables.Adjust
TAXII2_COLLECTIONS to the collections you want to ingest.Verifying the Connection
Confirm that Pulsedive indicators are flowing into OpenCTI before you rely on them in your workflows. OpenCTI’s ingestion manager polls on a schedule and imported data can take a few minutes to appear depending on platform load.- Open Data, then Ingestion, and confirm that your Pulsedive ingester is running.
- Open the knowledge base and confirm that Pulsedive indicators and observable entities are present.