You can export indicators in a hosted text file (External Dynamic list) from Cortex XSIAM or an engine using the Generic Export Indicators Service integration. Exported indicators can be used for example in firewall block lists, allow lists, and monitoring and analysis in Splunk. See Generic Export Indicators Service.
The Generic Export Indicators Service integration can be configured to export specific fields in different output formats. Multiple instances of the integration can be configured for different indicator queries, and the output can be customized to work with a variety of third-party services.
You can set up the Generic Export Indicators Service integration by setting up a long-running integration. See Forward Requests to Long-Running Integrations.
If you configure the Generic Export Indicator to run on-demand, use the !export-indicators-list-update
command for the first time to initialize the export process.