ExabeamSecOpsPlatform
Exabeam Security Operations Platform offers a centralized and scalable platform for log management.
- Category
- Analytics & SIEM
- Pack
- ExabeamSecurityOperationsPlatform
Configuration parameters
- url — Server URL (required)
- credentials — Client ID (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- isFetchEvents — Fetch events
- incidentFetchInterval — Incidents Fetch Interval
- eventFetchInterval — Events Fetch Interval
- max_fetch — Maximum Incidents Per Fetch
- max_events_fetch — Maximum Number of Cases Per Fetch
- fetch_query — Fetch query
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days)
- incidentType — Incident type
Commands (12)
- exabeam-get-threat-summary — Retrieve the Copilot Threat Summary for an individual alert.
- exabeam-platform-alert-search — Search for alerts that match one or more search criteria.
- exabeam-platform-case-search — Search for cases that match one or more search criteria. For example, you can search for cases that are associated with a specific case ID and that reference specific rules.
- exabeam-platform-context-table-delete — Delete a specific context table, including records and attributes.
- exabeam-platform-context-table-list — Retrieve metadata for all existing context tables, including source, operational status, and attribute mapping.
- exabeam-platform-create-case-note — Add a new note to the specified case.
- exabeam-platform-event-search — Get events from Exabeam Security Operations Platform.
- exabeam-platform-get-events — Get cases from Exabeam Security Operations Platform as Cortex XSIAM events. This command is supported in Cortex XSIAM only and is intended to be used for debugging purposes as it may result in duplicate events.
- exabeam-platform-list-case-notes — Retrieve a list of notes associated with the specified caseId.
- exabeam-platform-table-record-create — Add one or more context records directly to an existing table.
- exabeam-platform-table-record-list — Retrieve the records for a specific context table.
- exabeam-update-case-details — Update details for a specific case.