AlienVault USM Anywhere
Searches for and monitors alarms and events from AlienVault USM Anywhere.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- AlienVault_USM_Anywhere
Configuration parameters
- url — Server URL (e.g., https://www.example.com) (required)
- client_id — Client ID
- client_secret — Client Secret
- client_id_creds — Client ID
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- fetch_limit — Fetch Limit
- time_format — Time Format e.g. %Y-%m-%dT%H:%M:%SZ. Select "auto-discovery" to try to automatically determine the format.
Commands (4)
- alienvault-get-alarm — Retrieves details for an alarm.
- alienvault-get-events-by-alarm — Retrieves events associated with the specified alarm.
- alienvault-search-alarms — Retrieves alarms from AlienVault.
- alienvault-search-events — Searches for events in AlienVault USM Anywhere.