EDL Monitor
This integration can monitor EDLs by emailing the content of an EDL as a zipped file to a specified user at an interval (when run with a job), and/or simply monitor the EDL for availability and email the user if the EDL is not available in other playbooks
Utilities · EDL Monitor
Details
| ID | EDL Monitor |
|---|---|
| Provider | Palo Alto Networks |
| Category | Utilities |
| From Version | 6.0.0 |
| Docker Image | demisto/python3:3.12.8.3296088 |
| Supported Modules | Agentix XSIAM |
README
This integration can monitor EDLs by emailing the content of an EDL as a zipped file to a specified user at an interval (when run with a job), and/or simply monitor the EDL for availability and email the user if the EDL is not available in other playbooks
Configure EDL Monitor in Cortex
| Parameter | Description | Required |
|---|---|---|
| Timeout: | Timeout (in seconds) for how long to wait for EDL response before detecting as down (default 2 minutes) | False |
| Trust any certificate (not secure) | False | |
| Use system proxy settings | False | |
| Email server: | False | |
| Email username | False | |
| Email password | False |
Commands
You can execute these commands from the CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
get-edl-contents
Gets the current contents of an EDL
Base Command
get-edl-contents
Input
| Argument Name | Description | Required |
|---|---|---|
| EDL | EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). | Required |
| EDL_username | EDL username, for auth to the EDL (optional). | Optional |
| EDL_password | EDL password, for auth to the EDL (optional). | Optional |
Context Output
There is no context output for this command.
email-edl-contents
Gets the current contents of an EDL and emails it to a specified email address
Base Command
email-edl-contents
Input
| Argument Name | Description | Required |
|---|---|---|
| EDL | EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). | Required |
| Email address that you want to send the EDL contents to. | Required | |
| EDL_username | EDL username, for auth to the EDL (optional). | Optional |
| EDL_password | EDL password, for auth to the EDL (optional). | Optional |
Context Output
There is no context output for this command.
check-status
Return the response code of the EDL
Base Command
check-status
Input
| Argument Name | Description | Required |
|---|---|---|
| EDL | EDL IP or URL (e.g. http://xsoarserver.com:10009 or https://xsoarserver.com/instance/execute/instance_name). | Required |
| EDL_username | EDL username, for auth to the EDL (optional). | Optional |
| EDL_password | EDL password, for auth to the EDL (optional). | Optional |
| Email. | Optional |
Context Output
| Path | Type | Description |
|---|---|---|
| ResponseCode | number | The response code. |
Configuration parameters
timeout— Timeout:insecure— Trust any certificate (not secure)proxy— Use system proxy settingsemailServer— Email server:emailCredentials— Email username
Commands (3)
-
check-statusReturn the response code of the EDL
-
email-edl-contentsGets the current contents of an EDL and emails it to a specified email address
-
get-edl-contentsGets the current contents of an EDL
## EDL logger -You can use the playbook (or a cloned copy) with a job to check the EDL on a schedule, or you can use the integration commands in your own playbooks as needed -While the EDL contents are timestamped and attached in zip files, due to the nature of the files, zipping will likely not save much space Note: If you are a hosted customer, you may need to set the below server config: instance.execute.external = true [Reference](https://xsoar.pan.dev/docs/reference/integrations/edl) and configure the EDL to the below format: {base_url}/instance/execute/{edl_name} This is only tested with Gmail using smtp.gmail.com as the server, and you will need to enable 2FA for your google account and create an app password as the regular credentials will no longer work due to new Google security settings. See https://support.google.com/accounts/answer/185833?hl=en&authuser=2 for details