iDefense is a closed-source threat intelligence feed available to all Asset Manager customers. This feed correlates iDefense IPs against your network's IPs to produce actionable lists of zombie devices and threat flows in your network.
To use iDefense, you'll need to obtain an iDefense license key (not provided by FireMon). To produce threat flow results, you'll need a single source of NetFlow data such as Gigamon NetFlow. Asset Manager can receive NetFlow from a single source. If you have multiples, consider using a NetFlow aggregator. You will also need to direct the NetFlow results to your Asset Manager Command Center. These topics are out-of-scope for Asset Manager documentation, but your Solutions Architect and Support can nevertheless help with implementation. You do not need NetFlow data to show the zombie devices in your network. This dashboard is generated using native Asset Manager-indexed data. The iDefense feed is correlated against NetFlow data. The intersection of the two populates the threat_feed_ip table. Navigate to Settings > Tables > threat_feed_ip > View to open the table.
To configure the feed . . .
The NetFlow-capture service enables your Asset Manager Command Center to ingest NetFlow data. To enable NetFlow capture from the Asset Manager GUI: To enable NetFlow capture from the Asset Manager command-line interface: Configure the iDefense feed as follows: Enable NetFlow
The status of the service will change to Running.support service packetcapture start.