---
title: Get indicator feed data
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Intel](https://developers.cloudflare.com/api/python/resources/intel)

[Indicator Feeds](https://developers.cloudflare.com/api/python/resources/intel/subresources/indicator_feeds)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Get indicator feed data

intel.indicator\_feeds.data(intfeed\_id, IndicatorFeedDataParams\*\*kwargs) -> [IndicatorFeedDataResponse](<https://developers.cloudflare.com/api/python/resources/intel#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_data_response%20%3E%20(schema)>)

GET/accounts/{account\_id}/intel/indicator-feeds/{feed\_id}/data

Retrieves the raw data entries in a custom threat indicator feed.

##### Security

API Email + API Key

The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**`X-Auth-Email: user@example.com`

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**`X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194`

##### Accepted Permissions (at least one required)

`Intel Write``Intel Read`

##### ParametersExpand Collapse

account\_id: str

Identifier

maxLength32

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(method)%20data%20%3E%20(params)%20default%20%3E%20(param)%20account_id%20%3E%20(schema)>)

feed\_id: int

Indicator feed ID

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(method)%20data%20%3E%20(params)%20default%20%3E%20(param)%20feed_id%20%3E%20(schema)>)

##### ReturnsExpand Collapse

str

[Link to this property](<#(resource)%20intel.indicator_feeds%20%3E%20(model)%20indicator_feed_data_response%20%3E%20(schema)>)

### Get indicator feed data

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_email=os.environ.get("CLOUDFLARE_EMAIL"),  # This is the default and can be omitted
    api_key=os.environ.get("CLOUDFLARE_API_KEY"),  # This is the default and can be omitted
)
response = client.intel.indicator_feeds.data(
    feed_id=12,
    account_id="023e105f4ecef8ad9ca31a8372d0c353",
)
print(response)
```

##### Returns Examples