IBMSecurityVerify
IBM Security Verify provides a secure and scalable solution for collecting and managing security events from IBM Security Verify, offering advanced threat detection and response capabilities for protecting identities, applications, and data.
Analytics & SIEM · IBM Security Verify
Details
| ID | IBMSecurityVerify |
|---|---|
| Provider | IBM |
| Category | Analytics & SIEM |
| From Version | 8.4.0 |
| Docker Image | demisto/python3:3.12.13.10116658 |
| Supported Modules | XSIAM |
README
IBM Security Verify provides a secure and scalable solution for collecting and managing security events from IBM Security Verify, offering advanced threat detection and response capabilities for protecting identities, applications, and data.
Set up the Third Party System
To obtain the Client ID and Client Secret, follow these steps:
- Log in to the IBM Security Verify UI.
- Click the profile icon located at the top right corner of the interface.
- Select Switch to admin to access administrative settings.
- Navigate to Security > API Access.
- Click Add API Client to generate the necessary credentials.
- After clicking Add API Client, make sure to assign the following permissions to the API client:
- Manage reports
- Read reports
Configure IBM Security Verify on Cortex XSIAM
- Navigate to Settings > Configurations > Data Collection > Automations & Feed Integrations.
- Search for IBM Security Verify.
-
Click Add instance to create and configure a new integration instance.
Parameter Description Required Server URL For example: https://tenant.verify.ibm.com True Client ID True Client Secret True The maximum number of events per fetch The maximum is 50,000. True Trust any certificate (not secure) False Use system proxy settings False - Click Test to validate the URLs, token, and connection.
Commands
You can execute these commands from the Cortex XSIAM CLI, as part of an automation, or in a playbook.
After you successfully execute a command, a DBot message appears in the War Room with the command details.
ibm-security-verify-get-events
Retrieves events from IBM Security Verify.
Base Command
ibm-security-verify-get-events
Input
| Argument Name | Description | Required |
|---|---|---|
| should_push_events | If set to ‘True’, the command will create events; otherwise, it will only display them. Possible values are: True, False. Default is False. | Optional |
| limit | Maximum number of results to return. Default is 1000. | Optional |
| last_id | The ID of the last event retrieved. Use together with last_time for pagination to get events after this ID. Example: 1234abcd-5678-90ef-1234-567890abcdef. |
Optional |
| last_time | The timestamp of the last event retrieved. Use together with last_id for pagination to get events after this time. Example: 1672531200000. |
Optional |
| sort_order | Order to sort events by: ‘Desc’ or ‘Asc’. Possible values are: Desc, Asc. Default is Desc. | Optional |
Context Output
There is no context output for this command.
Configuration parameters
url— Server URL (required)credentials— Client ID (required)max_fetch— The maximum number of events per fetch (required)insecure— Trust any certificate (not secure)proxy— Use system proxy settings
Commands (1)
-
ibm-security-verify-get-eventsRetrieves events from IBM Security Verify.
category: Analytics & SIEM provider: IBM sectionorder: - Connect - Collect commonfields: id: IBMSecurityVerify version: -1 configuration: - display: Server URL name: url required: true type: 0 section: Connect additionalinfo: 'For example: https://tenant.verify.ibm.com' - display: Client ID name: credentials required: true section: Connect type: 9 displaypassword: Client Secret - display: The maximum number of events per fetch name: max_fetch additionalinfo: The maximum is 50,000. defaultvalue: 10000 section: Collect required: true type: 0 - display: Trust any certificate (not secure) name: insecure required: false type: 8 section: Connect - display: Use system proxy settings name: proxy required: false type: 8 section: Connect description: IBM Security Verify provides a secure and scalable solution for collecting and managing security events from IBM Security Verify, offering advanced threat detection and response capabilities for protecting identities, applications, and data. display: IBM Security Verify name: IBMSecurityVerify script: commands: - name: ibm-security-verify-get-events description: Retrieves events from IBM Security Verify. arguments: - name: should_push_events description: If set to 'True', the command will create events; otherwise, it will only display them. defaultValue: 'False' auto: PREDEFINED isArray: false predefined: - 'True' - 'False' - name: limit description: Maximum number of results to return. defaultValue: 1_000 - name: last_id description: "The ID of the last event retrieved. Use together with `last_time` to get events after this ID. Example: 1234abcd-5678-90ef-1234-567890abcdef." - name: last_time description: "The timestamp of the last event retrieved. Use together with `last_id` for pagination to get events after this time. Example: 1672531200000." - name: sort_order description: "Order to sort events by: 'Desc' or 'Asc'." defaultValue: 'Desc' auto: PREDEFINED predefined: - 'Desc' - 'Asc' dockerimage: demisto/python3:3.12.13.10116658 isfetchevents: true runonce: false script: '-' subtype: python3 type: python marketplaces: - marketplacev2 - platform fromversion: 8.4.0 tests: - No tests (auto formatted) supportedModules: - xsiam
