Sensor-level contents management

By default, Threat Intelligence contents can only be managed on the top-level sensor. However, this policy can be customized to allow any sensor in the solution to add, edit, enable or disable individual contents.

When the local management of Threat Intelligence (TI) contents is enabled, each sensor in the solution will allow the user to enable or disable any contents, and to define, edit and remove local contents. In this situation, any additions or changes performed on a Central Management Console (CMC) will not be propagated to the connected sensors.

When the local management of TI contents is disabled, each sensor in the solution will reflect exactly the contents defined on the top-level sensor. In this situation, any content added on the top sensor will be propagated to all connected sensors, and any content enabled or disabled will also be in the same state on all sensors. This also means that, when disabling the local management of contents, all custom contents created on the connected sensors will be erased.