EDL Monitor

This integration can monitor EDLs by emailing the content of an EDL as a zipped file to a specified user at an interval (when run with a job), and/or simply monitor the EDL for availability and email the user if the EDL is not available in other playbooks

Utilities · EDL Monitor

Details

IDEDL Monitor
ProviderPalo Alto Networks
CategoryUtilities
From Version6.0.0
Docker Imagedemisto/python3:3.12.8.3296088
Supported ModulesAgentix XSIAM

README

This integration can monitor EDLs by emailing the content of an EDL as a zipped file to a specified user at an interval (when run with a job), and/or simply monitor the EDL for availability and email the user if the EDL is not available in other playbooks

Configure EDL Monitor in Cortex

Parameter Description Required
Timeout: Timeout (in seconds) for how long to wait for EDL response before detecting as down (default 2 minutes) False
Trust any certificate (not secure)   False
Use system proxy settings   False
Email server:   False
Email username   False
Email password   False

Commands

You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.

get-edl-contents


Gets the current contents of an EDL

Base Command

get-edl-contents

Input

Argument Name Description Required
EDL EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). Required
EDL_username EDL username, for auth to the EDL (optional). Optional
EDL_password EDL password, for auth to the EDL (optional). Optional

Context Output

There is no context output for this command.

email-edl-contents


Gets the current contents of an EDL and emails it to a specified email address

Base Command

email-edl-contents

Input

Argument Name Description Required
EDL EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). Required
Email Email address that you want to send the EDL contents to. Required
EDL_username EDL username, for auth to the EDL (optional). Optional
EDL_password EDL password, for auth to the EDL (optional). Optional

Context Output

There is no context output for this command.

check-status


Return the response code of the EDL

Base Command

check-status

Input

Argument Name Description Required
EDL EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). Required
EDL_username EDL username, for auth to the EDL (optional). Optional
EDL_password EDL password, for auth to the EDL (optional). Optional
Email Email. Optional

Context Output

Path Type Description
ResponseCode number The response code.

Configuration parameters

  • timeout — Timeout:
  • insecure — Trust any certificate (not secure)
  • proxy — Use system proxy settings
  • emailServer — Email server:
  • emailCredentials — Email username

Commands (3)

  • check-status

    Return the response code of the EDL

  • email-edl-contents

    Gets the current contents of an EDL and emails it to a specified email address

  • get-edl-contents

    Gets the current contents of an EDL

## EDL logger
-You can use the playbook (or a cloned copy) with a job to check the EDL on a schedule, or you can use the integration commands in your own playbooks as needed
-While the EDL contents are timestamped and attached in zip files, due to the nature of the files, zipping will likely not save much space

Note: If you are a hosted customer, you may need to set the below server config:
instance.execute.external = true [Reference](https://xsoar.pan.dev/docs/reference/integrations/edl)
and configure the EDL to the below format:
{base_url}/instance/execute/{edl_name}

This is only tested with Gmail using smtp.gmail.com as the server, and you will need to enable 2FA for your google account and create an app password as the regular credentials will no longer work due to new Google security settings.  See https://support.google.com/accounts/answer/185833?hl=en&authuser=2 for details