Gigamon ThreatINSIGHT
Gigamon ThreatINSIGHT is a cloud-native network detection and response solution built for the rapid detection of threat activity, investigation of suspicious behavior, proactive hunting for potential risks, and directing a fast and effective response to active threats.
- Category
- Network Security
- Pack
- GigamonThreatINSIGHT
Configuration parameters
- api_key — API Token (required)
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days) (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- account_uuid — Incident Filter: Account UUID (Optional)
- max_fetch — Maximum incidents in each fetch each run
- incidentFetchInterval — Incidents Fetch Interval
Commands (16)
- insight-create-detection-rule — Create a new detection rule.
- insight-create-task — Create a new PCAP task.
- insight-get-detection-rule-events — Get a list of the events that matched on a specific rule.
- insight-get-detection-rules — Get a list of detection rules.
- insight-get-detections — Get a list of detections.
- insight-get-devices — Get a list of all devices.
- insight-get-entity-dhcp — Get DHCP information about an IP address.
- insight-get-entity-file — Get information about a file.
- insight-get-entity-pdns — Get passive DNS information about an IP or domain.
- insight-get-entity-summary — Get summary information about an IP or domain.
- insight-get-sensors — Get a list of all sensors.
- insight-get-tasks — Get a list of all the PCAP tasks.
- insight-get-telemetry-events — Get event telemetry data grouped by time.
- insight-get-telemetry-network — Get network telemetry data grouped by time
- insight-get-telemetry-packetstats — Get packetstats telemetry data grouped by time.
- insight-resolve-detection — Resolve a specific detection.