

# CreateThreatIntelSet
<a name="API_CreateThreatIntelSet"></a>

Creates a new ThreatIntelSet. ThreatIntelSets consist of known malicious IP addresses. GuardDuty generates findings based on ThreatIntelSets. Only users of the administrator account can use this operation.

## Request Syntax
<a name="API_CreateThreatIntelSet_RequestSyntax"></a>

```
POST /detector/detectorId/threatintelset HTTP/1.1
Content-type: application/json

{
   "activate": boolean,
   "clientToken": "string",
   "expectedBucketOwner": "string",
   "format": "string",
   "location": "string",
   "name": "string",
   "tags": { 
      "string" : "string" 
   }
}
```

## URI Request Parameters
<a name="API_CreateThreatIntelSet_RequestParameters"></a>

The request uses the following URI parameters.

 ** [detectorId](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-uri-DetectorId"></a>
The unique ID of the detector of the GuardDuty account for which you want to create a `threatIntelSet`.  
To find the `detectorId` in the current Region, see the Settings page in the GuardDuty console, or run the [ListDetectors](https://docs.aws.amazon.com/guardduty/latest/APIReference/API_ListDetectors.html) API.  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Required: Yes

## Request Body
<a name="API_CreateThreatIntelSet_RequestBody"></a>

The request accepts the following data in JSON format.

 ** [activate](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-activate"></a>
A Boolean value that indicates whether GuardDuty is to start using the uploaded ThreatIntelSet.  
Type: Boolean  
Required: Yes

 ** [clientToken](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-clientToken"></a>
The idempotency token for the create request.  
Type: String  
Length Constraints: Minimum length of 0. Maximum length of 64.  
Required: No

 ** [expectedBucketOwner](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-expectedBucketOwner"></a>
The AWS account ID that owns the Amazon S3 bucket specified in the **location** parameter.  
Type: String  
Length Constraints: Fixed length of 12.  
Required: No

 ** [format](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-format"></a>
The format of the file that contains the ThreatIntelSet.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Valid Values: `TXT | STIX | OTX_CSV | ALIEN_VAULT | PROOF_POINT | FIRE_EYE`   
Required: Yes

 ** [location](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-location"></a>
The URI of the file that contains the ThreatIntelSet.   
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Required: Yes

 ** [name](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-name"></a>
A user-friendly ThreatIntelSet name displayed in all findings that are generated by activity that involves IP addresses included in this ThreatIntelSet.  
Type: String  
Length Constraints: Minimum length of 1. Maximum length of 300.  
Required: Yes

 ** [tags](#API_CreateThreatIntelSet_RequestSyntax) **   <a name="guardduty-CreateThreatIntelSet-request-tags"></a>
The tags to be added to a new threat list resource.  
Type: String to string map  
Map Entries: Maximum number of 200 items.  
Key Length Constraints: Minimum length of 1. Maximum length of 128.  
Key Pattern: `^(?!aws:)[a-zA-Z+-=._:/]+$`   
Value Length Constraints: Maximum length of 256.  
Required: No

## Response Syntax
<a name="API_CreateThreatIntelSet_ResponseSyntax"></a>

```
HTTP/1.1 200
Content-type: application/json

{
   "threatIntelSetId": "string"
}
```

## Response Elements
<a name="API_CreateThreatIntelSet_ResponseElements"></a>

If the action is successful, the service sends back an HTTP 200 response.

The following data is returned in JSON format by the service.

 ** [threatIntelSetId](#API_CreateThreatIntelSet_ResponseSyntax) **   <a name="guardduty-CreateThreatIntelSet-response-threatIntelSetId"></a>
The ID of the ThreatIntelSet resource.  
Type: String

## Errors
<a name="API_CreateThreatIntelSet_Errors"></a>

For information about the errors that are common to all actions, see [Common Error Types](CommonErrors.md).

 ** AccessDeniedException **   
An access denied exception object.    
 ** Message **   
The error message.  
 ** Type **   
The error type.
HTTP Status Code: 403

 ** BadRequestException **   
A bad request exception object.    
 ** Message **   
The error message.  
 ** Type **   
The error type.
HTTP Status Code: 400

 ** InternalServerErrorException **   
An internal server error exception object.    
 ** Message **   
The error message.  
 ** Type **   
The error type.
HTTP Status Code: 500

## See Also
<a name="API_CreateThreatIntelSet_SeeAlso"></a>

For more information about using this API in one of the language-specific AWS SDKs, see the following:
+  [AWS Command Line Interface V2](https://docs.aws.amazon.com/goto/cli2/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for .NET V4](https://docs.aws.amazon.com/goto/DotNetSDKV4/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for C\$1\$1](https://docs.aws.amazon.com/goto/SdkForCpp/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for Go v2](https://docs.aws.amazon.com/goto/SdkForGoV2/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for Java V2](https://docs.aws.amazon.com/goto/SdkForJavaV2/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for JavaScript V3](https://docs.aws.amazon.com/goto/SdkForJavaScriptV3/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for Kotlin](https://docs.aws.amazon.com/goto/SdkForKotlin/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for PHP V3](https://docs.aws.amazon.com/goto/SdkForPHPV3/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for Python](https://docs.aws.amazon.com/goto/boto3/guardduty-2017-11-28/CreateThreatIntelSet) 
+  [AWS SDK for Ruby V3](https://docs.aws.amazon.com/goto/SdkForRubyV3/guardduty-2017-11-28/CreateThreatIntelSet) 