AWS - GuardDuty Event Collector
Amazon Web Services Guard Duty Service (gd) event collector integration for Cortex XSIAM.
- Category
- Analytics & SIEM
- Pack
- AWS-GuardDuty
Configuration parameters
- defaultRegion — AWS Default Region (required)
- roleArn — Role ARN
- roleSessionName — Role Session Name
- sessionDuration — Role Session Duration
- credentials — Access Key
- timeout — Timeout
- retries — Retries
- endpoint_url — PrivateLink service URL.
- sts_endpoint_url — STS PrivateLink URL.
- sts_regional_endpoint — AWS STS Regional Endpoints
- first_fetch — First fetch time
- limit — Number of events to fetch per fetch.
- gd_severity — Guard Duty Severity level (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- exclude_archived — Exclude archived/suppressed findings
- isFetchEvents — Fetch Events
- eventFetchInterval — Events Fetch Interval
Commands (1)
- aws-gd-get-events — Manual command used to fetch events and display them.