/
FireEyeHXEventCollector.yml
67 lines (67 loc) · 1.75 KB
/
FireEyeHXEventCollector.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
category: Analytics & SIEM
description: Palo Alto Networks FireEye HX Event Collector integration for XSIAM.
display: FireEye HX Event Collector
name: FireEye HX Event Collector
commonfields:
id: FireEye HX Event Collector
version: -1
configuration:
- display: Server URL (e.g., https://192.168.0.1:3000)
name: url
required: true
type: 0
- display: User Name
name: credentials
required: true
type: 9
- display: Trust any certificate (not secure)
name: insecure
required: false
type: 8
- display: Use system proxy settings
name: proxy
required: false
type: 8
- display: The maximum number of events per fetch.
additionalinfo: The maximum number of events to fetch every time fetch is executed.
defaultvalue: 1000
name: max_fetch
required: false
type: 0
section: Collect
- additionalinfo: The first fetch time, e.g., 1 hour, 3 days
display: First Fetch Time
defaultvalue: 3 days
name: first_fetch
required: false
type: 0
section: Collect
script:
commands:
- deprecated: false
description: Manual command to fetch events and display them.
name: fireeye-hx-get-events
arguments:
- name: limit
description: The maximum number of events to get.
- name: since
description: Occurrence time of the least recent event to include (inclusive).
defaultValue: 3 days
- auto: PREDEFINED
defaultValue: 'false'
description: If true, the command will create events, otherwise it will only display them.
name: should_push_events
predefined:
- 'true'
- 'false'
required: true
dockerimage: demisto/python3:3.10.11.61265
isfetchevents: true
script: '-'
subtype: python3
type: python
tests:
- No tests (auto formatted)
marketplaces:
- marketplacev2
fromversion: 6.8.0