---
title: "Creating and Adding Custom TIDE Feeds"
canonical: "https://docs.infoblox.com/space/BloxOneThreatDefense/35403424/Creating%20and%20Adding%20Custom%20TIDE%20Feeds"
format: markdown
---
## <span style="color: #000000">Creating a TIDE Profile for Custom TIDE Feeds (BYOF)</span>

<span style="color: #000000">Custom TIDE feeds can be added by first creating a new TIDE data profile and then adding a custom created TIDE feed to the profile. For information on creating TIDE data profiles, see </span><span style="color: #000000">*[Data Profiles](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35468021)*</span><span style="color: #000000">. </span>

> ℹ️ **Note**: A data profile must be associated with a governance policy before it can be used for an upload.

# TIDE Data Upload Workflow

TIDE’s Bring Your Own Feed (BYOF) enhancement allows administrators to configure an RPZ or feed with a URL-based data source. TIDE automatically imports and refreshes indicators from the source every hour. BYOF supports CSV and plain-text files, basic username and password authentication, and API-based imports. Administrators can view source details, associated RPZ or feed configurations, the most recent update time, and the number of imported indicators. 

The *Data Upload* page allows administrators to submit threat-intelligence indicator data to TIDE using either a local text file or a file hosted at a remote URL. Each upload must be associated with a data profile. The data profile determines the governance policy applied to the submitted indicators.

Once the feed is configured it will automatically update the content every hour. 

> ℹ️ **Note**: When configuring the feed, enable the egress IP addresses through your firewall as follows: **18.206.144.116** and **3.221.42.234**. Both IPs are located in the United States.

![Uploading a custom TIDE feed (BYOF) to TIDE. ](media://d56bdbdf-f9b5-432e-9edd-b2d8ded5b82f)

To upload indicator data, go to **Configure > Security > TIDE > Data Upload** and do the following.

## Step 1. Select a data profile

1. Open the **Select data profile** list.
2. Select the data profile that should be associated with the uploaded data.

## Step 2. Select the upload method

Choose one of the following upload methods.

### **File Upload**

Upload a data file from the local system.

### **URL Upload**

Retrieve data from a file hosted at a remote URL. The URL must point to a supported `.txt` file.

## Upload a local file

To upload a local indicator file, do the following.

  1. Select **File Upload**.
  2. Choose the data file from the local system.
  3. Verify that the file meets the required format and size limits.
  4. Select **Validate and Save**.

## Upload data from a URL

To upload indicator data from a remote URL, do the following.

  1. Select **URL Upload**.
  2. Enter the location of the file in the **URL** field.
  3. Confirm that the URL points to a supported `.txt` file.
  4. Enter the appropriate values in the **Username** and **Password** fields.
  5. Select **Validate and Save**.

## Available actions

### **Validate and Save**

The **Validate and Save** button validates the selected data profile, upload method, source, credentials, and indicator content. If validation succeeds, the upload is saved and submitted for processing. The upload result is recorded in **Upload History**. The button remains disabled until all required fields are completed.

### **Force Update**

The **Force Update** button immediately retrieves and processes data from a configured URL. Use this option to start an update without waiting for the next scheduled update interval. Feeds will automatically update the content every hour. **Force Update** applies to URL-based uploads and is available only after a valid URL upload has been configured.

## Upload History

The **Upload History** table records previous upload attempts. Administrators can review previous submissions in the *Upload History* table.

## <span style="color: #000000">Viewing Custom TIDE Feed Details</span>

<span style="color: #000000">Custom TIDE BYOF details can be viewed in the </span><span style="color: #000000">*Threat Feed Details*</span><span style="color: #000000"> panel in the Infoblox Portal. To view the </span><span style="color: #000000">*Threat Feed Details*</span><span style="color: #000000"> panel, log into the infoblox Portal and go to </span><span style="color: #000000">**Security**</span><span style="color: #000000"> > </span><span style="color: #000000">**Configuration**</span><span style="color: #000000"> > </span><span style="color: #000000">**On-Prem DNS Firewall**</span><span style="color: #000000">. In the </span><span style="color: #000000">*Threat Feed Details*</span><span style="color: #000000"> panel, you will find the address for your custom TIDE RPZ feed. On the </span><span style="color: #000000">**On-Prem DNS Firewall Policies **</span><span style="color: #000000">page, click </span><span style="color: #000000">**Feed Configuration Values **</span><span style="color: #000000">(Step 2) to view your organization's feeds, including your organization's custom created RPZ feeds. </span>

## <span style="color: #000000">Adding a Custom TIDE Feed to a Security Policy</span>

<span style="color: #000000">Custom TIDE feeds (TIDE BYOF feeds) can be added to a new or existing security policy as a policy rule. To add a custom TIDE feed to a security policy, do the following:</span>

1. <span style="color: #000000">Select </span><span style="color: #000000">*Feeds and Threat Insight*</span><span style="color: #000000"> as a rule type on the </span><span style="color: #000000">*Policy Rules*</span><span style="color: #000000"> pane. </span>
2. <span style="color: #000000">On the </span><span style="color: #000000">*Policy Rules*</span><span style="color: #000000"> pane, select </span><span style="color: #000000">**Feeds and Threat Insight**</span><span style="color: #000000"> as a rule type. </span>
3. <span style="color: #000000">From the </span><span style="color: #000000">*Name*</span><span style="color: #000000"> column, scroll through the list of available feeds under the </span><span style="color: #000000">**Choose a Feeds and Threat Insight**</span><span style="color: #000000"> menu until you locate the desired custom TIDE feed. The custom RPZ feed description is the same description as what was provided when the data profile for the feed was created. </span>
4. <span style="color: #000000">Select the custom TIDE feed from the feeds listed and apply an action (Action list) </span>
5. <span style="color: #000000">From the </span><span style="color: #000000">*Action*</span><span style="color: #000000"> column, select a rule action for the custom TIDE feed. Action options include: </span>
  - <span style="color: #000000">Allow - No Log</span>
  - <span style="color: #000000">Allow - With Log</span>
  - <span style="color: #000000">Block - No Redirect</span>
  - <span style="color: #000000">Block - Default Redirect</span>
  - <span style="color: #000000">Block - Custom Redirect</span>
  - <span style="color: #000000">Block (No Log) - No Redirect </span>
  - <span style="color: #000000">Block (No Log) - Default Redirect</span>
  - <span style="color: #000000">Block (No Log) - Custom Redirect</span>
6. <span style="color: #000000">Click </span><span style="color: #000000">**Next**</span><span style="color: #000000"> to complete the Security policy wizard, or click </span><span style="color: #000000">**Finish**</span><span style="color: #000000"> to finalize the security configuration process. </span>

<span style="color: #000000">For information on adding policy rules to a security policy, see </span><span style="color: #000000">*[Adding Policy Rules and Setting Precedence](https://infoblox-docs.atlassian.net/wiki/spaces/BloxOneThreatDefense/pages/35403288)*</span><span style="color: #000000">. </span>