Exabeam
The Exabeam Security Management Platform provides end-to-end detection, User Event Behavioral Analytics, and SOAR.
- Category
- Analytics & SIEM
- Pack
- Exabeam
Configuration parameters
- url — Server URL (e.g https://100.24.16.156:8484) (required)
- credentials — Username
- api_token — Username
- incident_type — Exabeam Incident Type
- priority — Priority
- status — Status
- isFetch — Fetch incidents
- max_fetch — Max incidents per fetch
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- look_back — Advanced: Minutes to look back when fetching
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetch_type — Fetch Type
- max_fetch_users — Max Users Per Fetch
- notable_users_fetch_interval — Notable Users Fetch Interval
- notable_users_first_fetch — Notable Users First Fetch Timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- minimum_risk_score_to_fetch_users — Minimum Risk Score To Fetch Users
Commands (38)
- exabeam-add-context-table-records — Add records to the context table.
- exabeam-add-context-table-records-from-csv — Add context table records from CSV file in a specific modification session.
- exabeam-delete-context-table-records — Delete records from a context table.
- exabeam-delete-watchlist — Deletes a watchlist.
- exabeam-fetch-rules — Gets all rules.
- exabeam-get-asset-data — Returns asset data.
- exabeam-get-asset-info — Returns asset information for given asset ID (hostname or IP address).
- exabeam-get-context-table-in-csv — Export a context table to CSV.
- exabeam-get-notable-assets — Returns notable assets.
- exabeam-get-notable-sequence-details — Returns sequence details for the given asset ID and time range.
- exabeam-get-notable-session-details — Returns notable session details.
- exabeam-get-notable-users — Returns notable users in a period of time.
- exabeam-get-peer-groups — Returns all peer groups.
- exabeam-get-rule-string — Gets a rule's information as a string.
- exabeam-get-rules-model-definition — Gets a rule model definition by name.
- exabeam-get-sequence-eventtypes — Returns sequence event types for the given asset sequence ID and time range.
- exabeam-get-session-info-by-id — Returns session info data for the given ID.
- exabeam-get-user-info — Returns user information data for the username.
- exabeam-get-user-labels — Returns all labels of the user.
- exabeam-get-user-sessions — Returns sessions for the given username and time range.
- exabeam-get-watchlists — Returns all watchlist IDs and titles.
- exabeam-list-asset-timeline-next-events — Gets next events for a given asset.
- exabeam-list-context-table-records — Returns a list of a context table records.
- exabeam-list-incident — Returns incidents from Exabeam.
- exabeam-list-security-alerts-by-asset — Gets security alerts for a given asset.
- exabeam-list-top-domains — List top domains of a sequence.
- exabeam-list-triggered-rules — Gets all the triggered rules of a sequence.
- exabeam-search-rules — Searches for rules by a keyword.
- exabeam-update-context-table-records — Updates records of a context table.
- exabeam-watchlist-add-items — Add watchlist items by their names or from a CSV file.
- exabeam-watchlist-asset-search — Gets the assets of a specified watchlist according to a keyword.
- exabeam-watchlist-remove-items — Removes items from a watchlist.
- get-notable-users — Returns notable users in a period of time.
- get-peer-groups — Returns all peer groups.
- get-user-info — Returns user information data for the username.
- get-user-labels — Returns all labels of the user.
- get-user-sessions — Returns sessions for the given username and time range.
- get-watchlists — Returns all watchlist IDs and titles.