DecyfirEventCollector

Collects event logs from DeCYFIR for ingestion into Cortex XSIAM.

Analytics & SIEM · DeCYFIR

Details

IDDecyfirEventCollector
ProviderCYFIRMA
CategoryAnalytics & SIEM
From Version8.4.0
Docker Imagedemisto/python3:3.12.13.10116658
Supported ModulesAgentix XSIAM

README

Collects event logs from DeCYFIR for ingestion into Cortex XSIAM.

Once configured, the integration periodically fetches event logs from DeCYFIR’s APIs and sends them to Cortex XSIAM for ingestion and analysis.

  • Events are fetched in real time (starting from the moment the integration is enabled).
  • Each event type (Access Logs, Assets Logs, Digital Risk Keywords Logs) is fetched separately using its own pagination and limit.
  • The integration automatically tracks and stores the last fetched timestamp and event IDs to prevent duplication.

Configure DeCYFIR Event Collector in Cortex

Parameter Required
Server URL True
API Key True
Event types to fetch True
Maximum number of Access Logs events per fetch False
Maximum number of Assets Logs events per fetch False
Maximum number of Digital Risk Keywords Logs events per fetch False
Trust any certificate (not secure) False
Use system proxy settings False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

decyfir-get-events


Retrieve Decyfir events manually. This command is used for developing/ debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.

Base Command

decyfir-get-events

Input

Argument Name Description Required
event_types Comma-separated list of event types to fetch. Possible values are: Access Logs, Assets Logs, Digital Risk Keywords Logs. Default is Access Logs,Assets Logs,Digital Risk Keywords Logs. Required
should_push_events Set this argument to True to send the fetched events to Cortex XSIAM. If False, the command will only display them in the War Room.
. Possible values are: True, False. Default is False.
Required
from_date Fetch events created after the specified time (e.g., “12 hours”, “7 days”). If not provided, defaults to “3 months”.
. Default is 3 months.
Optional

Context Output

There is no context output for this command.

Configuration parameters

  • url — Server URL (required)
  • credentials — (required)
  • event_types_to_fetch — Event types to fetch (required)
  • max_access_logs_events_per_fetch — Maximum number of Access Logs events per fetch
  • max_assets_logs_events_per_fetch — Maximum number of Assets Logs events per fetch
  • max_drkl_events_per_fetch — Maximum number of Digital Risk Keywords Logs events per fetch
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings

Commands (1)

  • decyfir-get-events

    Manual command to fetch events. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and API request limitation exceeding.

# DeCYFIR Event Collector

## Overview

Use this integration to collect Access Logs, Asset Logs, and Digital Risk Keyword Logs automatically from **DeCYFIR** into **Cortex XSIAM**.

[DeCYFIR](https://www.cyfirma.com/products/decyfir/) by **Cyfirma** combines cyber threat intelligence with indicators and risk insights to deliver predictive, personalized, contextual, and multi-layered threat intelligence.  

---

## Authorization

To use this integration, you must have a valid **DeCYFIR API Key**.

To obtain a commercial API key, contact **Cyfirma Support** at [contact@cyfirma.com](mailto:contact@cyfirma.com).  
Keep your API key secure — it carries all your privileges and should not be shared.