Hey Wendy,
To setup the Critical Stack Intel feed for Bro you can follow the instructions located at:
You can also find the instructions and usage tips on our wiki:
After installing the only thing you should need to do is to follow the onscreen prompts to:
sudo broctl check
sudo broctl install
sudo broctl restart **or** (assuming you are up to date on your SO patches) "sudo nsm_sensor_ps-restart --only-bro"
The nsm_sensor_ps-restart --only-bro gives you the advantage of starting bro as a non root user.
After Bro restarts you should see the feeds.bro file loaded:
/nsm/bro/logs$ zcat */loaded_scripts.* | grep feeds.bro
/opt/critical-stack/frameworks/intel/feeds.bro
A number of people on list have discussed leveraging the ability of SO to synch feeds from the master server to the other SO sensors. I would refer you to those other threads for the time being.
If you have any questions or problems with the client please feel free to open a ticket here:
V/r,
Liam Randall