CheckPointXDR
Fetch and manage incidents from Check Point XDR.
- Category
- Analytics & SIEM
- Pack
- CheckPointXDR
Configuration parameters
- url — Infinity XDR API URL (required)
- credentials — Client ID (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- first_fetch — First fetch time
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- close_out — Close Mirrored XDR Incidents
- mirror_direction — Incident Mirroring Direction
Commands (1)
- get-mapping-fields — Returns the list of fields to map in outgoing mirroring. This command is only used for debugging purposes.