-
Notifications
You must be signed in to change notification settings - Fork 1.6k
/
ArmisEventCollector.yml
72 lines (72 loc) · 2.11 KB
/
ArmisEventCollector.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
category: Analytics & SIEM
commonfields:
id: ArmisEventCollector
version: -1
configuration:
- defaultvalue: https://<armis-instance>.armis.com
display: Server URL
name: server_url
required: true
type: 0
section: Connect
- displaypassword: API Secret Key
additionalinfo: The API Secret Key allows you to programmatically integrate with the Armis ecosystem.
name: credentials
required: true
hiddenusername: true
type: 9
section: Connect
- display: Number of events to fetch per type
name: max_fetch
additionalinfo: The maximum number of events to fetch per event type.
type: 0
defaultvalue: 1000
section: Collect
- display: Trust any certificate (not secure)
name: insecure
type: 8
section: Connect
- display: Use system proxy settings
name: proxy
type: 8
section: Connect
- display: Event types to fetch
name: event_types_to_fetch
section: Collect
required: true
type: 16
defaultvalue: Alerts,Threat activities
options:
- Alerts
- Threat activities
description: Collects alerts & threat activities from Armis resources.
display: Armis Event Collector
name: ArmisEventCollector
supportlevelheader: xsoar
script:
commands:
- arguments:
- auto: PREDEFINED
defaultValue: 'false'
description: Set this argument to true in order to create events, otherwise the command will only display them.
name: should_push_events
predefined:
- 'true'
- 'false'
required: true
- description: The date from which to fetch events. The format should be YYYY-MM-DD or YYYY-MM-DDT:HH:MM:SS. If not specified, the current date will be used.
name: from_date
required: false
description: Manual command to fetch and display events. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.
name: armis-get-events
runonce: false
isfetchevents: true
script: '-'
type: python
subtype: python3
dockerimage: demisto/python3:3.10.13.78960
marketplaces:
- marketplacev2
fromversion: 6.10.0
tests:
- No tests (auto formatted)