Data Limits
Understand the data limits of various features in the Intel Exchange application.
Threat Data Limits
View Threat Data
At a time, you can view a maximum of 50,000 records in Threat Data.
Export Threat Data
At a time, you can export a maximum of 100,000 records from the Threat Data into a CSV file.
Threat Data Source Details
For threat data objects, analysts can view the latest seven entries of sources that sent threat intel to CTIX in Threat Data > Source Details. For indicators, analysts can view all entries. This functionality is not applicable to indicators.
IOC Lookup Limits
The maximum size of the excel sheet that you upload for the lookup is 10 MB.
From this excel sheet, a maximum of 10,000 records are taken up for the lookup. If there are more than 10,000 records, only the first ten thousand records are fetched.
API Feed Polling Data Limits
While configuring API feeds, you can poll for the last 15 days' data for API feed source providers.
If you need to extend the polled days limit beyond 15, contact Cyware Support.
Watchlist Limits
You can create a maximum of 100 watchlist records in the system.
Every watch list record created should at least consist of three characters.
Import Intel Limits
The Cyware CSV file size must be less than 10 MB. The first 10,000 records in the file are processed. Blank rows are also considered in the 10,000 records. If the file has more than 10,000 records, only the first 10,000 records are processed.
Run Rule Limits
For running the rule manually, you can select a maximum of 15 days worth of past data.
If you need to extend the polled days limit beyond 15, contact Cyware Support.
Threat Mailbox Limits
Any email in the threat mailbox that has total attachments above 10MB is not parsed.
At a time, a maximum of 50000 characters are parsed from the attachments.
You can create intel for a maximum of 4000 STIX objects at a time from the threat mailbox email attachments.
Quick Add Intel Limits
Using the Quick Add Intel feature, you can add intel to the Intel Exchange application by providing just a few details.
When passing data into Intel Exchange using the Free text, Import File, or from a URL, 50,000 characters are parsed in Intel Exchange at a time. If the URL, imported file, or free text submission has more than 50,000 characters then only the first 50,000 characters are parsed.
From these 50,000 characters parsed, intel is created for a maximum of 4000 STIX objects at a time in Intel Exchange.
Threat Bulletin Limits
The total size of a Threat Bulletin, including content and attachments, must be less than 10 MB. If the bulletin exceeds this limit, processing will be restricted to ensure optimal performance and system stability.
CQL Limits
This section outlines the limitations that apply when using Cyware Query Language (CQL) to search and filter threat data.
Parameter Limits
Date-based parameters support only exact dates. Relative date values such as Last 7 days, Last 15 days, or Last 1 month are not supported.
The Has Sighting parameter can return Location, Identity, and Observed Data objects. For these object types, sighting details may not be available in the object view.
Operator Limits
The following limitations apply to CQL operators:
The EXACTLY and ONLY IN operators apply only to the Source and Tags fields.
The ONLY IN operator supports a maximum of five values per query.
The MATCHES operator performs optimally for values up to 15 characters. For values longer than 15 characters, the operator may return false positives in the results.
Reports Limits
While scheduling a report, you can publish a maximum of 100,000 records at any moment in the Intel Exchange application.
Allowed Indicators Limits
You can add a maximum of 11,000 indicators to the allowed list in Intel Exchange if you are using Cyware On-Premise.
However, if you are using Cyware Cloud, you can add a maximum of 100,000 indicators to the allowed list.
Third-Party Ignored Indicators Limit
You can add a maximum of 1000 third-party ignored indicators in the Intel Exchange from the configured repository.
Audit Logs Limits
In Audit Log Management, administrators can view User (API) Activity Logs for the last 7 days.
Read-Only Users and Groups Limit
You can add a maximum of 100 read-only groups in the Intel Exchange application.
To determine the number of users with read-only permissions, the unique count of the number of users across all read-only groups will be calculated. For example, if User A is a member of two read-only groups, they will be counted as one read-only user.
The count of Read-Only users will only include active, non-Cyware users.
Custom Attributes Limits
The maximum supported size for the value of a custom attribute is 32 KB, equivalent to 32,766 characters. While ingesting, if a custom attribute value exceeds this limit, the additional characters are discarded.