ArmisEventCollector
Collects alerts, devices and activities from Armis resources.
- Category
- Analytics & SIEM
- Pack
- Armis
Configuration parameters
- server_url — Server URL (required)
- credentials — (required)
- max_fetch — Maximum number of events per fetch
- devices_max_fetch — Maximum number of device events per fetch
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- event_types_to_fetch — Event types to fetch (required)
- eventFetchInterval — Events Fetch Interval
- fetch_delay — Minutes to delay
- deviceFetchInterval — Device Fetch Interval
Commands (1)
- armis-get-events — Manual command to fetch and display events. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation.