Jask
Deprecated. Use Sumo Logic Cloud SIEM instead. Freeing the analyst with autonomous decisions.
- Category
- Analytics & SIEM
- Pack
- Jask
Configuration parameters
- URL — Server URL (required)
- Username — Username (required)
- APIKey — API Key (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetchQuery — Override default fetch query
- fetchLimit — Limit the maximum incidents amount per fetch
Commands (9)
- jask-get-entity-details — Get entity details for a specific entity ID
- jask-get-insight-comments — Get comments for a specific Insight ID. (Users can post and update comments on the JASK SIEM portal for any Insight ID.)
- jask-get-insight-details — Get Insight details for a specific Insight ID. Insight details command references SmartAlerts, which are the highest level abstractions in JASK SIEM consisting of multiple signals, and records and relating to one or more assets.
- jask-get-related-entities — Get entities related to a specific entity ID.
- jask-get-signal-details — Get Signal details for a specific Signal ID. Signal details command references signals in JASK which are created when records exhibit suspicious properties and mate with patterns or other detection logic.
- jask-get-whitelisted-entities — Get the entities on allow list.
- jask-search-entities — Search entities using the given filters.
- jask-search-insights — Search insights using the given filters.
- jask-search-signals — Search signals using the given filters.