Forcepoint DLP Event Collector
Use this integration to fetch security incidents from Forcepoint DLP as Cortex XSIAM events.
- Category
- Pack
- ForcepointDLP
Configuration parameters
- url — Server URL (e.g., https://<DLP Manager IP>:<DLP Manager port>/) (required)
- credentials — Username (required)
- max_fetch — Maximum number of events per fetch
- first_fetch — First fetch
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (1)
- forcepoint-dlp-get-events — Gets security events from Forcepoint DLP.