DecyfirEventCollector
Collects event logs from DeCYFIR for ingestion into Cortex XSIAM.
- Category
- Analytics & SIEM
- Pack
- DeCYFIR
Configuration parameters
- url — Server URL (required)
- credentials — (required)
- event_types_to_fetch — Event types to fetch (required)
- max_access_logs_events_per_fetch — Maximum number of Access Logs events per fetch
- max_assets_logs_events_per_fetch — Maximum number of Assets Logs events per fetch
- max_drkl_events_per_fetch — Maximum number of Digital Risk Keywords Logs events per fetch
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (1)
- decyfir-get-events — Manual command to fetch events. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and API request limitation exceeding.