/
CyberArkIdentityEventCollector.yml
84 lines (84 loc) · 2.03 KB
/
CyberArkIdentityEventCollector.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
category: Analytics & SIEM
sectionOrder:
- Connect
- Collect
commonfields:
id: CyberArk Identity Event Collector
version: -1
configuration:
- defaultvalue: https://<tenant>.my.idaptive.app
display: Server URL
name: url
required: true
type: 0
section: Connect
- defaultvalue: oauthsiem
display: App ID
name: app_id
required: true
type: 0
section: Collect
- display: User name
additionalinfo: The user name (admin@example.com) and password.
name: credentials
required: true
type: 9
section: Connect
- display: First fetch time
name: from
type: 0
defaultvalue: 3 days
required: true
section: Collect
- display: Maximum number of events per fetch
name: limit
type: 0
defaultvalue: 1000
required: true
section: Collect
- display: Trust any certificate (not secure)
name: insecure
type: 8
section: Connect
advanced: true
required: false
- display: Use system proxy settings
name: proxy
type: 8
section: Connect
advanced: true
required: false
description: This integration collects events from the Idaptive Next-Gen Access (INGA) using REST APIs.
display: CyberArk Identity Event Collector
name: CyberArk Identity Event Collector
script:
commands:
- description: 'Returns a list of events'
name: cyberarkidentity-get-events
arguments:
- description: The maximum number of events per fetch. Default is 1000.
defaultValue: 1000
isArray: true
name: limit
- description: Set this argument to True to create events, otherwise events will only be displayed.
auto: PREDEFINED
defaultValue: 'False'
name: should_push_events
predefined:
- 'True'
- 'False'
required: true
- description: First fetch time (<number> <time unit>, for example 12 hours, 1 day, 3 months). Default is 3 days.
isArray: true
name: from
runonce: false
script: '-'
isfetchevents: true
type: python
subtype: python3
dockerimage: demisto/fastapi:1.0.0.68195
marketplaces:
- marketplacev2
fromversion: 6.8.0
tests:
- No tests (auto formatted)