GoogleThreatIntelligenceRSAlerts
This integration allows the creation of incidents based on RS Alerts from Google Threat Intelligence.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- GoogleThreatIntelligence
Configuration parameters
- server_url — Server URL (required)
- credentials — (required)
- project_id — Project ID (required)
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
- first_fetch — First Fetch Time
- max_fetch — Max Fetch
- relevance_level — Relevance Level
- severity_level — Severity Level
- priority_level — Priority Level
- status — Status
- threat_scenarios — Threat Scenarios
- mirror_direction — Mirroring Direction
- reopen_incident_for_open_alert_status — Reopen Incident for Open Alert Status
- close_incident_for_close_alert_status — Close Incident for Close Alert Status
- alert_status_for_incident_reopen — Alert Status for Incident Reopen
- alert_status_for_incident_closure — Alert Status for Incident Closure
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
Commands (3)
- gti-rs-alert-get — Get a particular RS Alert by ID.
- gti-rs-alert-list — List the RS Alerts with provided filter arguments.
- gti-rs-alert-status-update — Update the status of an RS Alert.