AnomaliSecurityAnalyticsAlerts
The Anomali Security Analytics pack allows users to manage security alerts by interacting directly with the Anomali Security Analytics platform. It supports creating search jobs, monitoring their status, retrieving results, and updating alert statuses or comments, streamlining integration with Palo Alto XSOAR.
- Category
- Analytics & SIEM
- Pack
- AnomaliSecurityAnalyticsAlerts
Configuration parameters
- url — Server URL (required)
- credentials — Username (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- incidentType — Incident type
- fetch_query — Fetch query
- max_fetch — Maximum incidents to fetch.
- first_fetch — First fetch time
- incidentFetchInterval — Incidents Fetch Interval
Commands (4)
- anomali-security-analytics-alert-update — Update various fields of an alert including status, comment, assignee, severity, and owner.
- anomali-security-analytics-search-job-create — Create a new search job.
- anomali-security-analytics-search-job-results — Get search job results.
- anomali-security-analytics-search-job-status — Get the status of one or more search jobs.