CyberX - Central Manager

Updates alerts in CyberX Central Management.

Network Security · CyberX - Central Manager

Details

IDCyberX - Central Manager
ProviderMicrosoft
CategoryNetwork Security
From Version6.0.0
Docker Imagedemisto/python3-deb:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

cyberx-update-alert


Updating the alert

Base Command

cyberx-update-alert

Input

Argument Name Description Required
cyberx_uuid The unique ID. Required
action The action to perform on the alert. Possible values are: handle, handleAndLearn. Required

Context Output

There is no context output for this command.

Configuration parameters

  • Server — IP/DNS (required)
  • Api-Token — Token generated in CyberX (required)
  • proxy — Use system proxy settings
  • unsecure — Trust any certificate (not secure)

Commands (1)

  • cyberx-update-alert

    Updating the alert

For the CyberX Api Version 2.5

Allows Cortex XSOAR to integrate with CyberX and
perform actions with these alerts. 

To get the alerts from CyberX with UUID:
Send the data discovered by CyberX to Cortex XSOAR by defining a forwarding rule in the CyberX system (via QRadar forwarding  to a Cortex XSOAR Syslog Integration) and select the Remote support alert handling option which is only available in the QRadar option.