rsigma taxii store

Import a local STIX 2.1 bundle JSON file into an on-disk store (FsStore).

Requires the taxii-sync Cargo feature (included in prebuilt release binaries and the GHCR image built with --all-features).

Synopsis

rsigma taxii store --bundle <FILE> --store <DIR> [OPTIONS]

Use --bundle - to read bundle JSON from stdin.

Description

taxii store parses a STIX bundle from disk (or stdin) and imports it with FsStore::import_bundle. Validation uses the same Validator::producer_strict() profile as taxii sync — per-object validation before import, References phase skipped (appropriate for large bundles where refs resolve after the full import).

Re-running against the same store is idempotent: unchanged objects increment objects_deduplicated rather than objects_added.

Use this for air-gapped feeds, local MITRE ATT&CK JSON releases, CI fixtures, and development without a TAXII server. Network ingest remains taxii sync.

Flags

Required

Flag Description
--bundle <FILE> STIX bundle JSON path, or - for stdin.
--store <DIR> FsStore root directory (created when missing).

Import / validation

Flag Default Description
--bundle-id <ID> bundle file id Synthetic bundle id for export_bundle.
--allow-custom off Parse MITRE ATT&CK and other custom SDOs (x_* types). Required for enterprise ATT&CK bundle files.
--strict on Exit 1 when validation rejects one or more objects.
--allow-invalid off Import objects even when validation fails (diagnostics still recorded; conflicts with --strict).

Output

Structured summary via the global --output-format flag (json, ndjson, table, csv, tsv). Validation rejections are listed on stderr when progress output is enabled.

Exit codes

Code Meaning
0 Import completed; no validation rejections (or --allow-invalid).
1 Validation rejected one or more objects under default --strict.
3 Configuration, parse, or store error.

Examples

Import a local bundle into ./stix-store:

rsigma taxii store \
  --bundle ./feeds/indicators.json \
  --store ./stix-store

Import MITRE ATT&CK Enterprise release JSON (custom types):

rsigma taxii store \
  --bundle ./enterprise-attack-19.2.json \
  --store ./attck-store \
  --allow-custom

Pipe bundle JSON from another tool:

curl -fsS https://example.com/bundle.json | rsigma taxii store --bundle - --store ./stix-store

Point daemon enrichment at the same directory:

rsigma engine daemon -r rules/ \
  --stix-store ./attck-store \
  --enrichers enrichers.yml \
  --input http --output stdout

See also